LeadBooster Chatbot by Pipedrive Security & Risk Analysis

wordpress.org/plugins/leadbooster-by-pipedrive

LeadBooster Chatbot by Pipedrive is a chatbot plugin that captures visitors to your WordPress website and turns them from qualified leads into deals i …

3K active installs v1.1.1 PHP 5.6+ WP 4.5+ Updated Jan 21, 2026
chatcustomerlive-chatlivechatpipedrive
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LeadBooster Chatbot by Pipedrive Safe to Use in 2026?

Generally Safe

Score 100/100

LeadBooster Chatbot by Pipedrive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The leadbooster-by-pipedrive plugin version 1.1.1 exhibits a generally good security posture with several strong practices in place. The plugin has zero known vulnerabilities (CVEs) and no recorded history of past issues, which is a very positive indicator. Static analysis reveals a minimal attack surface, with only one AJAX handler, and importantly, this handler appears to have authentication and capability checks. The code also demonstrates good practices regarding SQL queries, all of which use prepared statements, and the presence of a nonce check. File operations and external HTTP requests are absent, further reducing potential risks.

However, there is a notable concern regarding output escaping. With 24 total outputs analyzed, only 21% are properly escaped. This means that a significant number of data outputs from the plugin may be vulnerable to cross-site scripting (XSS) attacks if untrusted data is processed and displayed without adequate sanitization. While the taint analysis showed zero flows with unsanitized paths and no critical or high-severity issues, the lack of robust output escaping on the majority of outputs presents a tangible risk that could be exploited. The absence of bundled libraries is a strength, as it avoids potential issues with outdated or vulnerable third-party code.

In conclusion, the plugin benefits from a clean vulnerability history and a well-controlled attack surface. The primary weakness lies in the insufficient output escaping, which is a common vector for XSS vulnerabilities. Addressing this would significantly strengthen the plugin's security. The overall risk is moderate, leaning towards lower due to the lack of historical issues and authentication controls on the entry point, but the XSS potential requires attention.

Key Concerns

  • Insufficient output escaping on most outputs
Vulnerabilities
None known

LeadBooster Chatbot by Pipedrive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LeadBooster Chatbot by Pipedrive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

21% escaped24 total outputs
Attack Surface

LeadBooster Chatbot by Pipedrive Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_pipedrive_delete_settings_from_dbincludes\admin.php:164
WordPress Hooks 6
actionadmin_menuincludes\admin.php:3
actionadmin_bar_menuincludes\admin.php:12
actionadmin_initincludes\core.php:7
actionwp_headincludes\embed.php:3
actionplugins_loadedpipedrive.php:19
actionadmin_enqueue_scriptspipedrive.php:42
Maintenance & Trust

LeadBooster Chatbot by Pipedrive Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version5.6
Downloads31K

Community Trust

Rating74/100
Number of ratings3
Active installs3K
Developer Profile

LeadBooster Chatbot by Pipedrive Developer Profile

Pipedrive

1 plugin · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LeadBooster Chatbot by Pipedrive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leadbooster-by-pipedrive/styles/admin.css/wp-content/plugins/leadbooster-by-pipedrive/scripts/admin.js/wp-content/plugins/leadbooster-by-pipedrive/scripts/fancyTable.min.js
Script Paths
/wp-content/plugins/leadbooster-by-pipedrive/scripts/admin.js/wp-content/plugins/leadbooster-by-pipedrive/scripts/fancyTable.min.js
Version Parameters
leadbooster-by-pipedrive/styles/admin.css?ver=leadbooster-by-pipedrive/scripts/admin.js?ver=leadbooster-by-pipedrive/scripts/fancyTable.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Start of the LeadBooster Chatbot by Pipedrive code --><!-- End of the LeadBooster Chatbot by Pipedrive Code. -->
Data Attributes
data-nonce="wp_create_nonce('delete_pipedrive_settings')"
FAQ

Frequently Asked Questions about LeadBooster Chatbot by Pipedrive