
LeadConnector Security & Risk Analysis
wordpress.org/plugins/leadconnectorConnect WordPress to LeadConnector for chat widgets, funnels, forms, calendars, reviews, custom values, and CRM tools.
Is LeadConnector Safe to Use in 2026?
Generally Safe
Score 95/100LeadConnector has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'leadconnector' plugin v3.0.24 exhibits a mixed security posture. On the positive side, static analysis indicates a strong adherence to secure coding practices regarding SQL queries and output escaping, with high percentages of prepared statements and properly escaped outputs. Furthermore, all identified entry points (AJAX, REST API, shortcodes, cron) appear to have authorization checks, which is a significant strength. The absence of critical or high severity taint flows is also reassuring.
However, several areas raise concerns. The presence of two known medium severity vulnerabilities in its history, specifically Cross-site Scripting and Missing Authorization, even though currently patched, indicates a pattern of past security weaknesses. The absence of nonce checks across all entry points is a notable oversight, potentially leaving the plugin vulnerable to CSRF attacks if authorization checks were ever bypassed or if specific actions were not properly protected. The taint analysis also flagged one flow with unsanitized paths, which warrants further investigation despite not being classified as critical or high severity in this analysis.
In conclusion, while the plugin demonstrates good practices in several key areas like SQL and output handling, the past vulnerability history and the lack of nonce checks present areas that require attention. The plugin's overall security is reasonably robust due to the current patching of known issues and the presence of authorization checks, but it is not without its risks.
Key Concerns
- Missing nonce checks on entry points
- Flows with unsanitized paths found
- Two medium severity CVEs in history
LeadConnector Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
LeadConnector < 3.0.22 - Missing Authorization
LeadConnector <= 3.0.21 - Missing Authorization
LeadConnector <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
LeadConnector Release Timeline
LeadConnector Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LeadConnector Attack Surface
REST API Routes 3
Shortcodes 6
WordPress Hooks 63
Scheduled Events 1
Maintenance & Trust
LeadConnector Maintenance & Trust
Maintenance Signals
Community Trust
LeadConnector Alternatives
Apricotrocket CRM Plugin
apricot-rocket-crm
Make your website interactive by adding an integrated CRM database, custom forms, email newsletters, marketing automation and drip marketing tool.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress
wp-fusion-lite
WP Fusion Lite synchronizes your WordPress users with contact records in your CRM or marketing automation system.
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
LeadConnector Developer Profile
1 plugin · 20K total installs
How We Detect LeadConnector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leadconnector/assets/css/custom-elementor.css/wp-content/plugins/leadconnector/assets/css/theme-fixes.cssleadconnector/assets/css/custom-elementor.css?ver=leadconnector/assets/css/theme-fixes.css?ver=HTML / DOM Fingerprints
data-lc-settingsleadconnector