LOYA.ID Easy Lead Form Security & Risk Analysis

wordpress.org/plugins/loya-id-easy-lead-form

Easily add a lead form to your WordPress site that integrates with the LOYA.ID CRM using a shortcode. Ideal for capturing leads with global phone supp …

0 active installs v1.0.3 PHP 7.4+ WP 6.0+ Updated Unknown
contact-formcrmlead-formloya-idshortcode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LOYA.ID Easy Lead Form Safe to Use in 2026?

Generally Safe

Score 100/100

LOYA.ID Easy Lead Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "loya-id-easy-lead-form" v1.0.3 demonstrates a generally strong security posture based on the provided static analysis. The absence of critical taint flows, raw SQL queries, and unprotected entry points is commendable. The high percentage of properly escaped output and the presence of nonce and capability checks (though zero capability checks were flagged, nonces are present) indicate good development practices regarding output sanitization and request verification.

However, there are a few areas for improvement. The lack of any recorded vulnerability history is positive, suggesting a history of secure development or responsible disclosure. Nevertheless, the presence of file operations and external HTTP requests, while not inherently risky, warrants careful review to ensure these operations are not exploitable. The plugin's attack surface is minimal, with only two shortcodes and no unprotected AJAX or REST API routes, further contributing to a secure profile.

In conclusion, this plugin appears to be well-developed from a security standpoint, with no immediate critical vulnerabilities detected. The primary areas for a deeper review would be the secure implementation of file operations and external HTTP requests. The consistent lack of reported vulnerabilities is a significant strength.

Key Concerns

  • No capability checks found
  • Presence of file operations
  • Presence of external HTTP requests
Vulnerabilities
None known

LOYA.ID Easy Lead Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LOYA.ID Easy Lead Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
28 escaped
Nonce Checks
4
Capability Checks
0
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

78% escaped36 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
handle_form_submission (public\class-lead-form.php:76)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LOYA.ID Easy Lead Form Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[loya_id_easy_lead_form] public\class-lead-form.php:8
[loya_id_easy_lead_form] trunk\public\class-lead-form.php:8
WordPress Hooks 10
actionadmin_menuadmin\class-admin-settings.php:8
actionadmin_initadmin\class-admin-settings.php:9
actionplugins_loadedloya-id-easy-lead-form.php:31
actionwp_enqueue_scriptspublic\class-lead-form.php:9
actioninitpublic\class-lead-form.php:10
actionadmin_menutrunk\admin\class-admin-settings.php:8
actionadmin_inittrunk\admin\class-admin-settings.php:9
actionplugins_loadedtrunk\loya-id-easy-lead-form.php:31
actionwp_enqueue_scriptstrunk\public\class-lead-form.php:9
actioninittrunk\public\class-lead-form.php:10
Maintenance & Trust

LOYA.ID Easy Lead Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads673

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LOYA.ID Easy Lead Form Developer Profile

loyadeveloper

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LOYA.ID Easy Lead Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/loya-id-easy-lead-form/assets/css/lead-form.css/wp-content/plugins/loya-id-easy-lead-form/assets/js/lead-form.js
Script Paths
https://www.google.com/recaptcha/api.js
Version Parameters
loya-id-easy-lead-form/assets/css/lead-form.css?ver=loya-id-easy-lead-form/assets/js/lead-form.js?ver=

HTML / DOM Fingerprints

CSS Classes
loya-id-lead-formform-groupcontrol-labelform-control
HTML Comments
<!-- Include a nonce for security -->
Data Attributes
data-sitekeyname="submit_lead_form"id="loya-id-lead-form"id="firstName"id="lastName"id="email"+3 more
JS Globals
grecaptcha
Shortcode Output
<h3 class="text-center" style="text-align: center;margin: 2px;font-weight: 600;">LOYA Lead Form</h3>
FAQ

Frequently Asked Questions about LOYA.ID Easy Lead Form