
Lead Forensics Security & Risk Analysis
wordpress.org/plugins/lead-forensics-roiLead Forensics helps you to turn your anonymous website visitors into paying customers. Our business database is the biggest in the world, so every vi …
Is Lead Forensics Safe to Use in 2026?
Generally Safe
Score 100/100Lead Forensics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lead-forensics-roi" plugin v3.3.11 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code appears to be free of dangerous functions, raw SQL queries, file operations, and external HTTP requests, all of which are positive security indicators. The presence of capability checks, though limited in number, is a good practice.
Despite these strengths, a minor concern arises from the output escaping. With only 33% of identified outputs properly escaped, there's a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly into the frontend without adequate sanitization. The lack of any identified taint flows and a clean vulnerability history are highly reassuring, suggesting the plugin has been well-maintained and hasn't historically been a target for exploitable vulnerabilities. The absence of any known CVEs, critical or otherwise, further strengthens this assessment.
In conclusion, the plugin demonstrates a robust foundation for security, primarily due to its minimal attack surface and the absence of common critical vulnerabilities. The primary area for potential improvement lies in ensuring all outputs are properly escaped to mitigate the risk of XSS. Overall, the plugin appears to be a secure choice, with the output escaping being the single, albeit moderate, concern identified.
Key Concerns
- Only 33% of outputs properly escaped
Lead Forensics Security Vulnerabilities
Lead Forensics Code Analysis
Output Escaping
Lead Forensics Attack Surface
WordPress Hooks 6
Maintenance & Trust
Lead Forensics Maintenance & Trust
Maintenance Signals
Community Trust
Lead Forensics Alternatives
Clickback
clickback-web-tracker
Clickback adds a small line of code to your WordPress site so you can identify companies who have visited your website but haven't converted.
Online Succes
online-succes
With this plugin you can easily add the Online Succes tracking code to your WordPress site.
IP Tracking by Gambit Nash
gn-ip-tracking
The IP Tracking plugin from Gambit Nash is an easy way to integrate our B2B IP Tracking service into your WordPress website.
Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices
woocommerce-wholesale-prices
WooCommerce wholesale plugin for serving wholesale & B2B customers. Adds wholesale pricing, user roles, dynamic pricing & more.
B2BKing — Ultimate WooCommerce B2B and Wholesale Solution — Dynamic Pricing, Wholesale Order Form & More
b2bking-wholesale-for-woocommerce
B2BKing is the complete solution for running a Wholesale, B2B or B2B + B2C hybrid store with WooCommerce.
Lead Forensics Developer Profile
1 plugin · 8K total installs
How We Detect Lead Forensics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lead-forensics-roi/js/custom.js/wp-content/plugins/lead-forensics-roi/js/custom.jsHTML / DOM Fingerprints
wp_ajax