LIQUID CONNECT Security & Risk Analysis

wordpress.org/plugins/liquid-connect

Pop-up, Random and A/B Testing banner.

400 active installs v1.1.7 PHP + WP 4.1+ Updated Dec 17, 2024
bannerctamarketingpopuprecommend
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LIQUID CONNECT Safe to Use in 2026?

Generally Safe

Score 92/100

LIQUID CONNECT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "liquid-connect" plugin v1.1.7 exhibits a strong adherence to several core WordPress security best practices, including the absence of known vulnerabilities, no reported CVEs, and the exclusive use of prepared statements for all SQL queries. The static analysis also indicates a minimal attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication checks. Furthermore, there are no recorded file operations or external HTTP requests that appear to be unprotected. This suggests a generally secure development approach.

However, a significant concern arises from the output escaping metric, where only 22% of outputs are properly escaped. This low percentage suggests a high probability of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be exploited to inject malicious scripts into web pages viewed by other users. The absence of nonce checks and capability checks on potential (though currently non-existent) entry points also presents a weakness. While the current attack surface is zero, any future additions without these crucial checks would immediately introduce significant risks.

In conclusion, while the plugin's history and core database interactions are reassuring, the substantial lack of output escaping is a critical flaw that severely undermines its security posture. The absence of active vulnerabilities is positive, but the identified coding practice makes it highly susceptible to XSS. Mitigating this output escaping issue should be the top priority to improve the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks on potential entry points
  • Missing capability checks on potential entry points
Vulnerabilities
None known

LIQUID CONNECT Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LIQUID CONNECT Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
230
64 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

22% escaped294 total outputs
Attack Surface

LIQUID CONNECT Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionget_headerliquid-connect.php:45
actionadmin_initliquid-connect.php:64
actionadmin_menuliquid-connect.php:80
actionwidgets_initliquid-connect.php:534
actionwp_enqueue_scriptsliquid-connect.php:542
actionadmin_noticesliquid-connect.php:557
actionget_headertrunk\liquid-connect.php:45
actionadmin_inittrunk\liquid-connect.php:64
actionadmin_menutrunk\liquid-connect.php:80
actionwidgets_inittrunk\liquid-connect.php:534
actionwp_enqueue_scriptstrunk\liquid-connect.php:542
actionadmin_noticestrunk\liquid-connect.php:557
Maintenance & Trust

LIQUID CONNECT Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2024
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

LIQUID CONNECT Developer Profile

lqd

9 plugins · 16K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
617 days
View full developer profile
Detection Fingerprints

How We Detect LIQUID CONNECT

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liquid-connect/css/liquid-connect.css/wp-content/plugins/liquid-connect/js/liquid-connect.js
Script Paths
/wp-content/plugins/liquid-connect/js/liquid-connect.js
Version Parameters
liquid-connect/css/liquid-connect.css?ver=liquid-connect/js/liquid-connect.js?ver=

HTML / DOM Fingerprints

CSS Classes
liquid-connect-formliquid-connect-button
Data Attributes
data-liquid-connect-iddata-liquid-connect-trackingdata-liquid-connect-target-visitordata-liquid-connect-target-devicesdata-liquid-connect-target-campaigndata-liquid-connect-trigger-page+8 more
JS Globals
liquid_connect_params
Shortcode Output
[liquid_connect_form][liquid_connect_button]
FAQ

Frequently Asked Questions about LIQUID CONNECT