Integration of Zoho CRM and WPForms Security & Risk Analysis

wordpress.org/plugins/integration-of-zoho-crm-and-wpforms

Visit plugin's website

100 active installs v1.0.7 PHP 5.6+ WP 5.0+ Updated Feb 19, 2026
wpforms-and-zohowpforms-with-zohozoho-and-wpformszoho-integrationzoho-with-wpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration of Zoho CRM and WPForms Safe to Use in 2026?

Generally Safe

Score 100/100

Integration of Zoho CRM and WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

This plugin, 'integration-of-zoho-crm-and-wpforms' v1.0.7, exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 100% of outputs being properly escaped. It also has a strong track record with zero recorded vulnerabilities (CVEs) to date, suggesting a generally well-maintained codebase. The usage of prepared statements for SQL queries is also a strength, with 77% of queries employing this secure method.

However, there are significant concerns regarding the attack surface. The plugin exposes one REST API route without any permission callbacks, making it an unprotected entry point. While there are no critical or high severity taint analysis findings, and no dangerous functions are detected, this unprotected REST API route is a direct pathway for potential exploitation. The limited number of capability checks (2) and nonce checks (4) in conjunction with the unprotected REST API route further amplify this risk. Without proper authorization checks, an unauthenticated user could potentially interact with this endpoint and cause unintended actions or information disclosure.

In conclusion, while the plugin benefits from strong output sanitization and a clean vulnerability history, the presence of an unprotected REST API route is a critical weakness. This single unprotected entry point significantly compromises the overall security posture, requiring immediate attention to implement proper authorization and permission checks.

Key Concerns

  • Unprotected REST API route
  • Low number of capability checks
Vulnerabilities
None known

Integration of Zoho CRM and WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integration of Zoho CRM and WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
10 prepared
Unescaped Output
0
22 escaped
Nonce Checks
4
Capability Checks
2
File Operations
5
External Requests
3
Bundled Libraries
0

SQL Query Safety

77% prepared13 total queries

Output Escaping

100% escaped22 total outputs
Attack Surface
1 unprotected

Integration of Zoho CRM and WPForms Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/bitwpfzc/redirectincludes\Integration\Integrations.php:210
WordPress Hooks 13
actionin_admin_headerincludes\Admin\Admin_Bar.php:16
actionadmin_menuincludes\Admin\Admin_Bar.php:17
actionadmin_enqueue_scriptsincludes\Admin\Admin_Bar.php:18
filterscript_loader_tagincludes\Admin\Admin_Bar.php:19
actionwpforms_process_completeincludes\Admin\WPF\Hooks.php:16
actionbitwpfzc_activationincludes\Core\Util\Activation.php:16
actionbitwpfzc_deactivationincludes\Core\Util\Deactivation.php:21
actionbitwpfzc_uninstallincludes\Core\Util\Uninstallation.php:20
actionrest_api_initincludes\Integration\Integrations.php:44
filterbitwpfzc_addRelatedListincludes\Integration\ZohoCRM\ZohoCRMHandler.php:337
actionplugins_loadedincludes\Plugin.php:38
actionadmin_noticesincludes\Plugin.php:47
actioninitincludes\Plugin.php:50
Maintenance & Trust

Integration of Zoho CRM and WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version5.6
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs100
Developer Profile

Integration of Zoho CRM and WPForms Developer Profile

formsintegrations

9 plugins · 980 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration of Zoho CRM and WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/css/bitforms-fields-style.css/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/css/style.css/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/js/setup.js
Script Paths
/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/js/setup.js
Version Parameters
integration-of-zoho-crm-and-wpforms/assets/js/setup.js?ver=

HTML / DOM Fingerprints

CSS Classes
bitforms-integration-fields
Data Attributes
data-bitforms-integration
JS Globals
bitwpfzc
REST Endpoints
/wp-json/bitwpfzc/redirect
FAQ

Frequently Asked Questions about Integration of Zoho CRM and WPForms