
Integration of Zoho CRM and WPForms Security & Risk Analysis
wordpress.org/plugins/integration-of-zoho-crm-and-wpformsVisit plugin's website
Is Integration of Zoho CRM and WPForms Safe to Use in 2026?
Generally Safe
Score 100/100Integration of Zoho CRM and WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, 'integration-of-zoho-crm-and-wpforms' v1.0.7, exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 100% of outputs being properly escaped. It also has a strong track record with zero recorded vulnerabilities (CVEs) to date, suggesting a generally well-maintained codebase. The usage of prepared statements for SQL queries is also a strength, with 77% of queries employing this secure method.
However, there are significant concerns regarding the attack surface. The plugin exposes one REST API route without any permission callbacks, making it an unprotected entry point. While there are no critical or high severity taint analysis findings, and no dangerous functions are detected, this unprotected REST API route is a direct pathway for potential exploitation. The limited number of capability checks (2) and nonce checks (4) in conjunction with the unprotected REST API route further amplify this risk. Without proper authorization checks, an unauthenticated user could potentially interact with this endpoint and cause unintended actions or information disclosure.
In conclusion, while the plugin benefits from strong output sanitization and a clean vulnerability history, the presence of an unprotected REST API route is a critical weakness. This single unprotected entry point significantly compromises the overall security posture, requiring immediate attention to implement proper authorization and permission checks.
Key Concerns
- Unprotected REST API route
- Low number of capability checks
Integration of Zoho CRM and WPForms Security Vulnerabilities
Integration of Zoho CRM and WPForms Code Analysis
SQL Query Safety
Output Escaping
Integration of Zoho CRM and WPForms Attack Surface
REST API Routes 1
WordPress Hooks 13
Maintenance & Trust
Integration of Zoho CRM and WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Integration of Zoho CRM and WPForms Alternatives
Integration of Zoho CRM and Contact Form 7
integration-of-zoho-crm-and-contact-form-7
Visit plugin's website
Integrations of Zoho CRM with Elementor form
integrations-of-zoho-crm-with-elementor-form
Visit plugin's website
Integrations of Zoho Campaigns with Elementor form
integrations-of-zoho-campaigns-with-elementor-form
Visit plugin's website
Catalyst Connect Zoho CRM Client Portal
catalyst-connect-client-portal
The plugin utilizes data directly from the Zoho CRM and allows the user to pick and choose which data is visible on your website.
Connect Form for Elementor and Zoho CRM
connect-form-for-elementor-zoho-crm
Grow your business with automated lead capture. Our plugin integrates Elementor forms directly with Zoho CRM, saving you time and ensuring accurate cu …
Integration of Zoho CRM and WPForms Developer Profile
9 plugins · 980 total installs
How We Detect Integration of Zoho CRM and WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/css/bitforms-fields-style.css/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/css/style.css/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/js/setup.js/wp-content/plugins/integration-of-zoho-crm-and-wpforms/assets/js/setup.jsintegration-of-zoho-crm-and-wpforms/assets/js/setup.js?ver=HTML / DOM Fingerprints
bitforms-integration-fieldsdata-bitforms-integrationbitwpfzc/wp-json/bitwpfzc/redirect