Integration for Elementor forms – Sendinblue Security & Risk Analysis

wordpress.org/plugins/integration-for-elementor-forms-sendinblue

Connect your Elementor Pro forms to Sendinblue/Brevo to easily capture and manage contacts from your website.

7K active installs v2.1.1 PHP 7.0+ WP 5.0+ Updated Jan 23, 2026
brevoelementorelementor-proformssendinblue
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Integration for Elementor forms – Sendinblue Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for Elementor forms – Sendinblue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'integration-for-elementor-forms-sendinblue' plugin, version 2.1.1, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with all analyzed output being properly escaped and no critical or high severity taint flows identified. The absence of file operations and dangerous functions further contributes to its secure design. Furthermore, the plugin has no recorded history of vulnerabilities, suggesting a diligent approach to security by the developers.

However, there are areas that warrant attention. The plugin makes five external HTTP requests, which, while not inherently insecure, represent potential points of failure or compromise if the external services are not secured. The SQL query usage is mixed, with 33% not using prepared statements, which could be a risk for SQL injection if the unsanitized inputs are directly incorporated. While only one AJAX handler exists and it benefits from a nonce check, a larger attack surface of entry points, even if currently protected, always carries a small inherent risk. The limited number of capability checks (two) is also worth noting; while the existing checks are likely sufficient for the current functionality, an expansion of features could necessitate more robust permission controls.

In conclusion, this plugin appears to be well-secured with no known critical vulnerabilities. The developers have implemented good output escaping and no dangerous code patterns. The main areas for improvement lie in minimizing the risk associated with external HTTP requests and ensuring all SQL queries are properly parameterized. The absence of past vulnerabilities is a positive indicator of ongoing developer commitment to security.

Key Concerns

  • SQL queries not using prepared statements
  • External HTTP requests made
Vulnerabilities
None known

Integration for Elementor forms – Sendinblue Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integration for Elementor forms – Sendinblue Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
2 prepared
Unescaped Output
0
7 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

33% prepared6 total queries

Output Escaping

100% escaped7 total outputs
Attack Surface

Integration for Elementor forms – Sendinblue Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_sendinblue_clear_attributes_cacheincludes\class-sendinblue-integration-action.php:14
WordPress Hooks 10
actionelementor/editor/after_enqueue_scriptsincludes\class-sendinblue-integration-action.php:15
actionplugins_loadedincludes\class-sendinblue-migration.php:43
actionadmin_noticesincludes\class-sendinblue-migration.php:44
actionadmin_initincludes\class-sendinblue-migration.php:45
actionplugins_loadedincludes\class-sendinblue-migration.php:442
filterplugin_action_links_integration-for-elementor-forms-sendinblue/sendinblue-elementor-integration.phpincludes\settings.php:12
actionadmin_menuincludes\settings.php:19
actionadmin_initincludes\settings.php:20
actionelementor_pro/initinit-sendinblue-integration-action.php:12
actionadmin_noticessendinblue-elementor-integration.php:29
Maintenance & Trust

Integration for Elementor forms – Sendinblue Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.0
Last updatedJan 23, 2026
PHP min version7.0
Downloads72K

Community Trust

Rating96/100
Number of ratings20
Active installs7K
Developer Profile

Integration for Elementor forms – Sendinblue Developer Profile

Webtica

4 plugins · 7K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Elementor forms – Sendinblue

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-elementor-forms-sendinblue/assets/css/sendinblue-integration.css/wp-content/plugins/integration-for-elementor-forms-sendinblue/assets/js/sendinblue-integration.js
Script Paths
/wp-content/plugins/integration-for-elementor-forms-sendinblue/assets/js/sendinblue-integration.js
Version Parameters
integration-for-elementor-forms-sendinblue/assets/css/sendinblue-integration.css?ver=integration-for-elementor-forms-sendinblue/assets/js/sendinblue-integration.js?ver=

HTML / DOM Fingerprints

CSS Classes
sendinblue-integration-field-wrappersendinblue-integration-field-settings
HTML Comments
<!-- Sendinblue Integration - Elementor Action --><!-- Start Sendinblue integration --><!-- End Sendinblue integration -->
Data Attributes
data-sendinblue-attributedata-sendinblue-type
JS Globals
SendinblueIntegrationSendinblueAttributesManager
REST Endpoints
/wp-json/sendinblue-integration/v1/attributes
FAQ

Frequently Asked Questions about Integration for Elementor forms – Sendinblue