
Leadinfo Security & Risk Analysis
wordpress.org/plugins/leadinfoThis plugin can be used to add the Leadinfo tracking code to a Wordpress site
Is Leadinfo Safe to Use in 2026?
Generally Safe
Score 98/100Leadinfo has a strong security track record. Known vulnerabilities have been patched promptly.
The "leadinfo" plugin v2.1.4 exhibits a mixed security posture. On the positive side, static analysis indicates a small attack surface with no unprotected entry points and a good use of prepared statements for SQL queries. The presence of nonce and capability checks also suggests an attempt to implement security measures. However, there are areas of concern, particularly the 50% rate of unescaped output, which could lead to Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed two flows with unsanitized paths, though they were not classified as critical or high severity, they still represent potential entry points for malicious data.
The plugin's vulnerability history is a significant red flag. With two known medium-severity CVEs, and a recent vulnerability recorded in May 2025, it indicates a recurring pattern of security weaknesses. The common types of vulnerabilities being Missing Authorization and CSRF further suggest issues with how user actions and data access are handled. While there are currently no unpatched CVEs, the history of past issues, especially those related to authorization, raises concerns about the overall robustness of the plugin's security controls. Therefore, while the plugin demonstrates some good security practices in its code, the historical vulnerability data and the presence of unsanitized paths warrant caution.
Key Concerns
- Unescaped output rate is 50%
- Taint analysis shows 2 unsanitized path flows
- 2 known medium severity CVEs in history
Leadinfo Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Leadinfo <= 1.1 - Missing Authorization to Unauthenticated Settings Change
Leadinfo <= 1.0 - Cross-Site Request Forgery
Leadinfo Code Analysis
Output Escaping
Data Flow Analysis
Leadinfo Attack Surface
REST API Routes 1
WordPress Hooks 3
Maintenance & Trust
Leadinfo Maintenance & Trust
Maintenance Signals
Community Trust
Leadinfo Alternatives
Webmetic
webmetic
Easily integrate Webmetic into your WordPress website by adding your Account ID.
Online Succes
online-succes
With this plugin you can easily add the Online Succes tracking code to your WordPress site.
Miraget B2B Leads generation
miraget-b2b-leads-generation
MiragetLeads is a powerful free open-source plugin for B2B websites which performs data capture on users visiting your website anonymously.
IP2GA
ip2ga
Track all user activities on the site, including page views, button clicks, and form submissions, and send them to Google Analytics 4.
Mcc Automated
mobile-cost-control-automated
Get accurate information from your prospect's bills and show them a better offer instantly. Show your prospects their line count, total bill, dat …
Leadinfo Developer Profile
1 plugin · 7K total installs
How We Detect Leadinfo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leadinfo/admin/js/settings.js/wp-content/plugins/leadinfo/admin/css/settings.csshttps://cdn.leadinfo.net/ping.jsHTML / DOM Fingerprints
<!-- Leadinfo tracking code -->data-leadinfo-idleadinfoGlobalLeadinfoNamespace/wp-json/leadinfo/v1/tracker_code