Leadster Marketing Conversacional: O Futuro da Geração de Leads

5K active installs v1.3.2 PHP 7.0+ WP 5.0+ Updated Nov 26, 2024
geracao-de-leadsleadsleadstermarketingmarketing-conversacional
91
A · Safe
CVEs total2
Unpatched0
Last CVENov 16, 2023
Download
Safety Verdict

Is Leadster Safe to Use in 2026?

Generally Safe

Score 91/100

Leadster has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Nov 16, 2023Updated 1yr ago
Risk Assessment

The 'leadster-marketing-conversacional' plugin version 1.3.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with zero identified entry points and no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and having a high percentage of properly escaped output. The presence of a nonce check is also a positive indicator.

However, there are notable concerns. The taint analysis reveals a flow with an unsanitized path, which, while not classified as critical or high, still indicates a potential for malicious data to be processed without adequate cleaning. The plugin's vulnerability history is also a significant point of concern, with two known medium-severity CVEs, both of which were reportedly Cross-Site Request Forgery (CSRF) vulnerabilities. The fact that these were medium-severity and the plugin has historically had CSRF issues suggests a recurring pattern that needs attention, especially given that no unpatched CVEs are currently listed.

In conclusion, while the plugin demonstrates some strong security foundations, the presence of unsanitized paths in the taint analysis and the history of CSRF vulnerabilities, even if currently patched, warrant careful consideration. The absence of capability checks on potential (though currently non-existent) entry points is also a weakness that could become problematic if the attack surface expands in future versions.

Key Concerns

  • Taint flow with unsanitized path detected
  • History of 2 medium severity CVEs (CSRF)
  • No capability checks on potential entry points
Vulnerabilities
2

Leadster Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2023-47791medium · 4.3Cross-Site Request Forgery (CSRF)

Leadster <= 1.1.2 - Cross-Site Request Forgery via leadster_script_code_action

Nov 16, 2023 Patched in 1.1.3 (68d)
CVE-2023-41668medium · 4.3Cross-Site Request Forgery (CSRF)

Leadster <= 1.1.2 - Cross-Site Request Forgery

Sep 4, 2023 Patched in 1.1.3 (141d)
Code Analysis
Analyzed Mar 16, 2026

Leadster Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped14 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
leadster_script_code_action (leadster.php:101)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Leadster Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedleadster.php:216
actionadmin_menuleadster.php:218
actionadmin_noticesleadster.php:221
actionadmin_print_stylesleadster.php:225
actionadmin_post_leadster_script_codeleadster.php:227
actionwp_footerleadster.php:229
Maintenance & Trust

Leadster Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 26, 2024
PHP min version7.0
Downloads42K

Community Trust

Rating100/100
Number of ratings3
Active installs5K
Developer Profile

Leadster Developer Profile

Leadster

1 plugin · 5K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
105 days
View full developer profile
Detection Fingerprints

How We Detect Leadster

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leadster-marketing-conversacional/assets/css/style.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Leadster