
Leadster Security & Risk Analysis
wordpress.org/plugins/leadster-marketing-conversacionalLeadster Marketing Conversacional: O Futuro da Geração de Leads
Is Leadster Safe to Use in 2026?
Generally Safe
Score 91/100Leadster has a strong security track record. Known vulnerabilities have been patched promptly.
The 'leadster-marketing-conversacional' plugin version 1.3.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with zero identified entry points and no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and having a high percentage of properly escaped output. The presence of a nonce check is also a positive indicator.
However, there are notable concerns. The taint analysis reveals a flow with an unsanitized path, which, while not classified as critical or high, still indicates a potential for malicious data to be processed without adequate cleaning. The plugin's vulnerability history is also a significant point of concern, with two known medium-severity CVEs, both of which were reportedly Cross-Site Request Forgery (CSRF) vulnerabilities. The fact that these were medium-severity and the plugin has historically had CSRF issues suggests a recurring pattern that needs attention, especially given that no unpatched CVEs are currently listed.
In conclusion, while the plugin demonstrates some strong security foundations, the presence of unsanitized paths in the taint analysis and the history of CSRF vulnerabilities, even if currently patched, warrant careful consideration. The absence of capability checks on potential (though currently non-existent) entry points is also a weakness that could become problematic if the attack surface expands in future versions.
Key Concerns
- Taint flow with unsanitized path detected
- History of 2 medium severity CVEs (CSRF)
- No capability checks on potential entry points
Leadster Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Leadster <= 1.1.2 - Cross-Site Request Forgery via leadster_script_code_action
Leadster <= 1.1.2 - Cross-Site Request Forgery
Leadster Code Analysis
Output Escaping
Data Flow Analysis
Leadster Attack Surface
WordPress Hooks 6
Maintenance & Trust
Leadster Maintenance & Trust
Maintenance Signals
Community Trust
Leadster Alternatives
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation
sumome
Sumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.
Funnel
funnel
Streamline Your Marketing: Effortlessly Navigate User Conversion Paths
LeadSource Tracker – Free Edition
leadsource-tracker
LeadSource Tracker is a simple campaign and marketing attribution that tracks multiple lead sources per visitor.
MetricSpot SEO Leads
metricspot-seo-leads
With MetricSpot's SEO Leads Plugin you will be able to offer free SEO reports on your own website. Automate the process of capturing SEO leads!
Slide to Subscribe
slide-to-subscribe
Allow people to subscribe to your newsletter with just a slide. Works with any newsletter or website, extremely easy setup.
Leadster Developer Profile
1 plugin · 5K total installs
How We Detect Leadster
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leadster-marketing-conversacional/assets/css/style.css