Miraget B2B Leads generation Security & Risk Analysis

wordpress.org/plugins/miraget-b2b-leads-generation

MiragetLeads is a powerful free open-source plugin for B2B websites which performs data capture on users visiting your website anonymously.

10 active installs v2.3.1 PHP 5.7+ WP 4.7+ Updated Dec 25, 2020
analyticsb2bleadsmiraget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Miraget B2B Leads generation Safe to Use in 2026?

Generally Safe

Score 85/100

Miraget B2B Leads generation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'miraget-b2b-leads-generation' plugin v2.3.1 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities (CVEs) and a lack of significant attack surface through AJAX, REST API, shortcodes, or cron events are positive indicators. The presence of nonce checks and capability checks, while limited, suggests some effort towards secure coding practices. However, the static analysis reveals several areas of concern. A significant portion of SQL queries do not utilize prepared statements, increasing the risk of SQL injection. Furthermore, a low percentage of output is properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The taint analysis is particularly concerning, with a high number of flows (9 out of 11) having unsanitized paths, five of which are flagged as high severity. This indicates potential vulnerabilities where user-supplied data could be used in a harmful way. The vulnerability history being clear of any recorded issues might suggest a lack of prior scrutiny or that vulnerabilities have been successfully mitigated, but the current code analysis highlights immediate risks that need addressing. Overall, while the plugin has a clean vulnerability history and a small attack surface, the high number of unsanitized taint flows and insecure SQL queries represent substantial risks that require urgent attention.

Key Concerns

  • High number of unsanitized taint flows
  • Significant percentage of SQL queries not prepared
  • Low percentage of properly escaped output
  • Limited nonce and capability checks
Vulnerabilities
None known

Miraget B2B Leads generation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Miraget B2B Leads generation Code Analysis

Dangerous Functions
0
Raw SQL Queries
21
16 prepared
Unescaped Output
70
21 escaped
Nonce Checks
5
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

43% prepared37 total queries

Output Escaping

23% escaped91 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

11 flows9 with unsanitized paths
mblg_active_company_render_list_page (includes\functions.php:539)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Miraget B2B Leads generation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterset-screen-optionincludes\BackMain.php:19
actionadmin_menuincludes\BackMain.php:20
actionadmin_enqueue_scriptsincludes\BackMain.php:22
actionadmin_menuincludes\functions.php:406
actionadmin_menuincludes\functions.php:534
actionadmin_menuincludes\functions.php:573
actionadmin_menuincludes\functions.php:616
filterscript_loader_tagleadsgen-master.php:97
actionwp_enqueue_scriptsleadsgen-master.php:105
actionadmin_footerleadsgen-master.php:138
actionadmin_enqueue_scriptsleadsgen-master.php:141
actionwp_footerleadsgen-master.php:145
actionwp_footerleadsgen-master.php:164
Maintenance & Trust

Miraget B2B Leads generation Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedDec 25, 2020
PHP min version5.7
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Miraget B2B Leads generation Developer Profile

amhallam

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Miraget B2B Leads generation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/miraget-b2b-leads-generation/assets/css/front-style.css/wp-content/plugins/miraget-b2b-leads-generation/assets/js/form.js/wp-content/plugins/miraget-b2b-leads-generation/assets/js/form.min.js
Script Paths
https://miraget.com/api/jsapp.js

HTML / DOM Fingerprints

CSS Classes
mblg-form
Data Attributes
data-url="https://miraget.com/api/api.php"
FAQ

Frequently Asked Questions about Miraget B2B Leads generation