
Miraget B2B Leads generation Security & Risk Analysis
wordpress.org/plugins/miraget-b2b-leads-generationMiragetLeads is a powerful free open-source plugin for B2B websites which performs data capture on users visiting your website anonymously.
Is Miraget B2B Leads generation Safe to Use in 2026?
Generally Safe
Score 85/100Miraget B2B Leads generation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'miraget-b2b-leads-generation' plugin v2.3.1 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities (CVEs) and a lack of significant attack surface through AJAX, REST API, shortcodes, or cron events are positive indicators. The presence of nonce checks and capability checks, while limited, suggests some effort towards secure coding practices. However, the static analysis reveals several areas of concern. A significant portion of SQL queries do not utilize prepared statements, increasing the risk of SQL injection. Furthermore, a low percentage of output is properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. The taint analysis is particularly concerning, with a high number of flows (9 out of 11) having unsanitized paths, five of which are flagged as high severity. This indicates potential vulnerabilities where user-supplied data could be used in a harmful way. The vulnerability history being clear of any recorded issues might suggest a lack of prior scrutiny or that vulnerabilities have been successfully mitigated, but the current code analysis highlights immediate risks that need addressing. Overall, while the plugin has a clean vulnerability history and a small attack surface, the high number of unsanitized taint flows and insecure SQL queries represent substantial risks that require urgent attention.
Key Concerns
- High number of unsanitized taint flows
- Significant percentage of SQL queries not prepared
- Low percentage of properly escaped output
- Limited nonce and capability checks
Miraget B2B Leads generation Security Vulnerabilities
Miraget B2B Leads generation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Miraget B2B Leads generation Attack Surface
WordPress Hooks 13
Maintenance & Trust
Miraget B2B Leads generation Maintenance & Trust
Maintenance Signals
Community Trust
Miraget B2B Leads generation Alternatives
IP2GA
ip2ga
Track all user activities on the site, including page views, button clicks, and form submissions, and send them to Google Analytics 4.
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation
sumome
Sumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.
Leadinfo
leadinfo
This plugin can be used to add the Leadinfo tracking code to a Wordpress site
Leadfeeder by Dealfront
dealfront
Turn page views into pipeline.
RAEK First-Party Data Collection
raek-real-time-identification
One tool to collect, organize and utilize your first-party data, so you can turn more visitors into buyers.
Miraget B2B Leads generation Developer Profile
1 plugin · 10 total installs
How We Detect Miraget B2B Leads generation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/miraget-b2b-leads-generation/assets/css/front-style.css/wp-content/plugins/miraget-b2b-leads-generation/assets/js/form.js/wp-content/plugins/miraget-b2b-leads-generation/assets/js/form.min.jshttps://miraget.com/api/jsapp.jsHTML / DOM Fingerprints
mblg-formdata-url="https://miraget.com/api/api.php"