LA CRM Integration with Contact Form Security & Risk Analysis

wordpress.org/plugins/la-crm-integration-with-contact-form

This plugin helps to manage leads from Contact form 7.

10 active installs v2.1 PHP + WP 3.3+ Updated Nov 21, 2024
contact-formcontact-form-7crmless-annoyingless-annoying-crm
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LA CRM Integration with Contact Form Safe to Use in 2026?

Generally Safe

Score 92/100

LA CRM Integration with Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "la-crm-integration-with-contact-form" plugin v2.1 exhibits a generally positive security posture with no recorded vulnerabilities or critical code signals. The absence of known CVEs and the low number of identified code issues are encouraging. The plugin demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and the presence of a nonce check, however minimal, is a positive sign for input validation. Taint analysis also shows no critical or high-severity unsanitized flows, indicating a low risk of code injection or path traversal vulnerabilities through the analyzed paths.

However, there are areas for improvement. The plugin's output escaping is only moderately effective, with 58% of outputs not properly escaped. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is incorporated into these unescaped outputs. Furthermore, the lack of capability checks on any entry points, combined with the absence of any identified entry points at all, suggests a limited attack surface or a potential oversight in how the plugin handles potential privileged actions. While the current analysis indicates zero unprotected entry points, a comprehensive audit of all potential interaction points is recommended to ensure robustness.

In conclusion, this plugin appears to be relatively secure, primarily due to the lack of historical vulnerabilities and the secure handling of database interactions. The primary concern lies in the insufficient output escaping, which could lead to XSS. Addressing this and ensuring all potential user-facing functionalities are appropriately secured with capability checks would significantly enhance its security standing.

Key Concerns

  • Insufficient output escaping
  • No capability checks on entry points
Vulnerabilities
None known

LA CRM Integration with Contact Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LA CRM Integration with Contact Form Release Timeline

v2.0
v1.0
Code Analysis
Analyzed Apr 16, 2026

LA CRM Integration with Contact Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped24 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<licf-api-options> (admin/licf-api-options.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LA CRM Integration with Contact Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsinit/licf-functions.php:8
actionadmin_menuinit/licf-functions.php:25
filterwpcf7_editor_panelsinit/licf-functions.php:41
actionwpcf7_save_contact_forminit/licf-functions.php:241
actionwpcf7_mail_sentinit/licf-functions.php:311
actionadmin_noticesla-crm-integration-with-contact-form.php:31
actionadmin_initla-crm-integration-with-contact-form.php:40
Maintenance & Trust

LA CRM Integration with Contact Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 21, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LA CRM Integration with Contact Form Developer Profile

Yudiz Solutions Pvt. Ltd.

15 plugins · 6K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
59 days
View full developer profile
Detection Fingerprints

How We Detect LA CRM Integration with Contact Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/la-crm-integration-with-contact-form/css/licf-admin-style.css
Version Parameters
la-crm-integration-with-contact-form/css/licf-admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
licf-contact-fieldslicf-settings
Data Attributes
name="allow-crm"name="what-to-create"name="name"name="email"name="phone"name="company-name"+3 more
FAQ

Frequently Asked Questions about LA CRM Integration with Contact Form