Integrations of Zoho CRM with Elementor form Security & Risk Analysis

wordpress.org/plugins/integrations-of-zoho-crm-with-elementor-form

Visit plugin's website

300 active installs v1.0.8 PHP 5.6+ WP 5.1+ Updated Jun 19, 2025
elementor-and-zohoelementor-with-zohozoho-and-elementorzoho-integrationzoho-with-elementor
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMay 7, 2025
Safety Verdict

Is Integrations of Zoho CRM with Elementor form Safe to Use in 2026?

Mostly Safe

Score 78/100

Integrations of Zoho CRM with Elementor form is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: May 7, 2025Updated 9mo ago
Risk Assessment

The plugin 'integrations-of-zoho-crm-with-elementor-form' v1.0.8 exhibits a mixed security posture. On one hand, the static analysis reveals a commendable lack of direct entry points like AJAX handlers, REST API routes, and shortcodes, with no detected 'Dangerous functions' or unsanitized taint flows. All output appears to be properly escaped, and the majority of SQL queries utilize prepared statements. However, there are several areas of concern that temper this positive outlook.

The plugin has a known, currently unpatched medium severity vulnerability from 2025-05-07, specifically an 'Open Redirect'. This is a significant weakness, as unpatched vulnerabilities are a primary attack vector. While the static analysis shows limited direct attack surface, the presence of file operations and external HTTP requests, even if not explicitly flagged as problematic in this analysis, warrant careful consideration, especially in conjunction with the known open redirect history. The limited number of capability checks and nonce checks, while not necessarily indicative of a vulnerability in this specific scan, suggest that if any vulnerabilities *were* present in the code, they might be exploitable with fewer restrictions.

In conclusion, while the plugin demonstrates good practices in output sanitization and SQL query preparation, the presence of an unpatched medium severity vulnerability (Open Redirect) and the use of file operations and external HTTP requests represent notable weaknesses. The lack of a large attack surface is a strength, but it does not entirely mitigate the risk posed by the known vulnerability and the potential for issues within the file/HTTP operations.

Key Concerns

  • Currently unpatched medium severity CVE
Vulnerabilities
1

Integrations of Zoho CRM with Elementor form Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47644medium · 6.1URL Redirection to Untrusted Site ('Open Redirect')

Integrations of Zoho CRM with Elementor form <= 1.0.7 - Open Redirect

May 7, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Integrations of Zoho CRM with Elementor form Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
12 prepared
Unescaped Output
0
15 escaped
Nonce Checks
1
Capability Checks
1
File Operations
3
External Requests
3
Bundled Libraries
0

SQL Query Safety

63% prepared19 total queries

Output Escaping

100% escaped15 total outputs
Attack Surface

Integrations of Zoho CRM with Elementor form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionizcrmef_activationincludes\Core\Util\Activation.php:16
actionizcrmef_deactivationincludes\Core\Util\Deactivation.php:21
actionizcrmef_uninstallincludes\Core\Util\UnInstallation.php:23
Maintenance & Trust

Integrations of Zoho CRM with Elementor form Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 19, 2025
PHP min version5.6
Downloads6K

Community Trust

Rating74/100
Number of ratings3
Active installs300
Developer Profile

Integrations of Zoho CRM with Elementor form Developer Profile

formsintegrations

9 plugins · 980 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integrations of Zoho CRM with Elementor form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrations-of-zoho-crm-with-elementor-form/assets/images/elementor-zoho-icon.svg
Script Paths
/wp-content/plugins/integrations-of-zoho-crm-with-elementor-form/assets/js/elementor-zoho-crm.js/wp-content/plugins/integrations-of-zoho-crm-with-elementor-form/assets/js/front-end.js/wp-content/plugins/integrations-of-zoho-crm-with-elementor-form/assets/js/editor.js
Version Parameters
integrations-of-zoho-crm-with-elementor-form/assets/js/elementor-zoho-crm.js?ver=integrations-of-zoho-crm-with-elementor-form/assets/js/front-end.js?ver=integrations-of-zoho-crm-with-elementor-form/assets/js/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
izcrmef-admin-formizcrmef-admin-inputizcrmef-admin-labelizcrmef-admin-button
HTML Comments
<!-- If try to direct access plugin folder it will Exit --><!-- The admin menu and page handler class --><!-- Register the admin menu --><!-- Load the asset libraries -->
Data Attributes
data-izcrmef-field
JS Globals
window.IZCRMEF_Adminwindow.IZCRMEF_Frontend
REST Endpoints
/wp-json/izcrmef/v1/settings/wp-json/izcrmef/v1/forms
Shortcode Output
[izcrmef_form]
FAQ

Frequently Asked Questions about Integrations of Zoho CRM with Elementor form