Integration for Gravity Forms with Zoho CRM Security & Risk Analysis

wordpress.org/plugins/integration-for-gravity-forms-and-zoho

Integration for Gravity Forms with Zoho CRM is a Zoho CRM integration plugin for WordPress that makes it really simple to send your Gravity forms dire …

10 active installs v1.0.3 PHP 5.3+ WP 4.5+ Updated Oct 15, 2021
crm-lead-magnetgravity-formslead-magnetzoho-add-onzoho-crm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Integration for Gravity Forms with Zoho CRM Safe to Use in 2026?

Generally Safe

Score 85/100

Integration for Gravity Forms with Zoho CRM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

This plugin exhibits a concerning security posture due to a significant number of unprotected AJAX endpoints and the presence of a dangerous function. The static analysis reveals four AJAX handlers, all of which lack authentication checks, presenting a wide attack surface that could be exploited by unauthenticated users. Furthermore, the use of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution (RCE) if not handled with extreme care and proper sanitization of the serialized data, which is not indicated in the analysis.

While the plugin shows good practices in other areas such as SQL statement preparation and output escaping, these strengths are overshadowed by the fundamental security flaws. The taint analysis showing three high-severity flows, coupled with the lack of nonce and capability checks, strongly suggests that data processed by these AJAX endpoints might be vulnerable to manipulation. The absence of any recorded vulnerability history might indicate it hasn't been a target or has flown under the radar, but this should not be mistaken for inherent security. The critical weaknesses identified in the static analysis demand immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Dangerous function: unserialize
  • High severity taint flows
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Integration for Gravity Forms with Zoho CRM Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Integration for Gravity Forms with Zoho CRM Code Analysis

Dangerous Functions
4
Raw SQL Queries
5
5 prepared
Unescaped Output
6
81 escaped
Nonce Checks
0
Capability Checks
0
File Operations
7
External Requests
10
Bundled Libraries
0

Dangerous Functions Found

unserialize$igzf_zoho_meta_data = unserialize($igzf_zoho_meta);admin\admin.php:111
unserialize$modulename= unserialize($value->form_data)['module'];admin\admin.php:263
unserialize$layout= unserialize($value->form_data)['layout'];admin\admin.php:264
unserialize$mapping_data= unserialize($gf_zoho);function.php:126

SQL Query Safety

50% prepared10 total queries

Output Escaping

93% escaped87 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
zgfgetCrmFields (function.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Integration for Gravity Forms with Zoho CRM Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_zgfgetCrmFieldsfunction.php:2
authwp_ajax_zgfmodulelistfunction.php:23
authwp_ajax_zgfgetuserlistfunction.php:37
authwp_ajax_zgfdeleteFormfunction.php:56
WordPress Hooks 3
actionadmin_menuadmin\admin.php:7
actiongform_after_submissionfunction.php:70
actionadmin_enqueue_scriptsgravityforms-zoho.php:34
Maintenance & Trust

Integration for Gravity Forms with Zoho CRM Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 15, 2021
PHP min version5.3
Downloads917

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Integration for Gravity Forms with Zoho CRM Developer Profile

Ignizee

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Gravity Forms with Zoho CRM

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-gravity-forms-and-zoho/css/style.css/wp-content/plugins/integration-for-gravity-forms-and-zoho/customscript.js
Script Paths
/wp-content/plugins/integration-for-gravity-forms-and-zoho/customscript.js
Version Parameters
integration-for-gravity-forms-and-zoho/css/style.css?ver=1.1

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
name='igzf_zoho_fields'name='modulename'name='moduleList'name='layoutlist'name='usertype'
JS Globals
myAjax
FAQ

Frequently Asked Questions about Integration for Gravity Forms with Zoho CRM