Integration of Zoho CRM and Gravity Forms Security & Risk Analysis

wordpress.org/plugins/integration-of-zoho-crm-and-gravity-forms

Visit plugin's website

20 active installs v1.0.3 PHP 5.6+ WP 5.0+ Updated Dec 6, 2023
apigravity-formsleadszohozoho-crm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration of Zoho CRM and Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Integration of Zoho CRM and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "integration-of-zoho-crm-and-gravity-forms" plugin, at version 1.0.3, presents a mixed security posture. On the positive side, it demonstrates good practices by properly escaping all output and utilizing prepared statements for the vast majority of its SQL queries. The absence of known vulnerabilities in its history and no critical findings in taint analysis are also encouraging signs, suggesting a generally well-developed codebase regarding common injection and data manipulation risks.

However, a significant concern arises from its attack surface. The plugin exposes one REST API route that lacks permission callbacks. This means that any unauthenticated user could potentially interact with this endpoint, leading to unauthorized actions or information disclosure if the endpoint performs sensitive operations. While the static analysis did not reveal specific dangerous functions or unsanitized paths, the presence of an unprotected REST API route is a clear security gap that needs immediate attention.

In conclusion, the plugin has a strong foundation in output sanitization and secure database interaction. Nevertheless, the unprotected REST API route represents a critical weakness. Addressing this specific entry point should be the priority to improve its overall security posture, as it introduces a direct risk of unauthorized access and potential exploitation.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Integration of Zoho CRM and Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integration of Zoho CRM and Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
10 prepared
Unescaped Output
0
22 escaped
Nonce Checks
4
Capability Checks
2
File Operations
5
External Requests
3
Bundled Libraries
0

SQL Query Safety

83% prepared12 total queries

Output Escaping

100% escaped22 total outputs
Attack Surface
1 unprotected

Integration of Zoho CRM and Gravity Forms Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/bitgfzc/redirectincludes\Integration\Integrations.php:206
WordPress Hooks 13
actionin_admin_headerincludes\Admin\Admin_Bar.php:16
actionadmin_menuincludes\Admin\Admin_Bar.php:17
actionadmin_enqueue_scriptsincludes\Admin\Admin_Bar.php:18
filterscript_loader_tagincludes\Admin\Admin_Bar.php:19
actiongform_after_submissionincludes\Admin\GF\Hooks.php:16
actionbitgfzc_activationincludes\Core\Util\Activation.php:16
actionbitgfzc_deactivationincludes\Core\Util\Deactivation.php:21
actionbitgfzc_uninstallincludes\Core\Util\Uninstallation.php:20
actionrest_api_initincludes\Integration\Integrations.php:40
filterbitgfzc_addRelatedListincludes\Integration\ZohoCRM\ZohoCRMHandler.php:336
actionplugins_loadedincludes\Plugin.php:37
actioninitincludes\Plugin.php:45
actionadmin_noticesincludes\Plugin.php:62
Maintenance & Trust

Integration of Zoho CRM and Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 6, 2023
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Integration of Zoho CRM and Gravity Forms Developer Profile

formsintegrations

9 plugins · 980 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration of Zoho CRM and Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-of-zoho-crm-and-gravity-forms/assets/css/style.css/wp-content/plugins/integration-of-zoho-crm-and-gravity-forms/assets/js/index.js
Script Paths
/wp-content/plugins/integration-of-zoho-crm-and-gravity-forms/assets/js/index.js
Version Parameters
/wp-content/plugins/integration-of-zoho-crm-and-gravity-forms/assets/js/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
bitgfzc
Data Attributes
data-noncedata-assetsurldata-baseurldata-ajaxurldata-allformsdata-erase_all+5 more
JS Globals
bitgfzc
REST Endpoints
/wp-json/bitgfzc/redirect
FAQ

Frequently Asked Questions about Integration of Zoho CRM and Gravity Forms