
LeadConnector Security & Risk Analysis
wordpress.org/plugins/leadconnectorLeadConnector: It helps you to add the LeadConnector chat widget and the LeadConnector funnel pages to your WordPress website.
Is LeadConnector Safe to Use in 2026?
Generally Safe
Score 95/100LeadConnector has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'leadconnector' plugin v3.0.24 exhibits a mixed security posture. On the positive side, static analysis indicates a strong adherence to secure coding practices regarding SQL queries and output escaping, with high percentages of prepared statements and properly escaped outputs. Furthermore, all identified entry points (AJAX, REST API, shortcodes, cron) appear to have authorization checks, which is a significant strength. The absence of critical or high severity taint flows is also reassuring.
However, several areas raise concerns. The presence of two known medium severity vulnerabilities in its history, specifically Cross-site Scripting and Missing Authorization, even though currently patched, indicates a pattern of past security weaknesses. The absence of nonce checks across all entry points is a notable oversight, potentially leaving the plugin vulnerable to CSRF attacks if authorization checks were ever bypassed or if specific actions were not properly protected. The taint analysis also flagged one flow with unsanitized paths, which warrants further investigation despite not being classified as critical or high severity in this analysis.
In conclusion, while the plugin demonstrates good practices in several key areas like SQL and output handling, the past vulnerability history and the lack of nonce checks present areas that require attention. The plugin's overall security is reasonably robust due to the current patching of known issues and the presence of authorization checks, but it is not without its risks.
Key Concerns
- Missing nonce checks on entry points
- Flows with unsanitized paths found
- Two medium severity CVEs in history
LeadConnector Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
LeadConnector < 3.0.22 - Missing Authorization
LeadConnector <= 3.0.21 - Missing Authorization
LeadConnector <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
LeadConnector Release Timeline
LeadConnector Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LeadConnector Attack Surface
REST API Routes 3
Shortcodes 6
WordPress Hooks 63
Scheduled Events 1
Maintenance & Trust
LeadConnector Maintenance & Trust
Maintenance Signals
Community Trust
LeadConnector Alternatives
Flamingo
flamingo
A trustworthy message storage plugin for Contact Form 7.
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
LeadConnector Developer Profile
1 plugin · 30K total installs
How We Detect LeadConnector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leadconnector/assets/css/custom-elementor.css/wp-content/plugins/leadconnector/assets/css/theme-fixes.cssleadconnector/assets/css/custom-elementor.css?ver=leadconnector/assets/css/theme-fixes.css?ver=HTML / DOM Fingerprints
data-lc-settingsleadconnector