mosparo Integration Security & Risk Analysis

wordpress.org/plugins/mosparo-integration

The plugin adds the functionality to use mosparo in WordPress forms or forms from Contact Form 7, Everest Form, and other plugins.

700 active installs v1.16.0 PHP 7.4+ WP 5.4+ Updated Feb 21, 2026
api-clientformsintegrationmosparospam-protection
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is mosparo Integration Safe to Use in 2026?

Generally Safe

Score 100/100

mosparo Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The mosparo-integration plugin version 1.16.0 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, and shortcodes with any attack surface significantly reduces the potential for direct exploitation. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing a decent percentage of output escaping. The presence of nonce and capability checks also indicates an awareness of common WordPress security vulnerabilities.

However, a concern arises from the taint analysis, which identified one flow with an unsanitized path. While not classified as critical or high severity, this could indicate a potential vulnerability if this path is user-controllable and leads to sensitive operations or information disclosure. The plugin also makes one external HTTP request, which, while not inherently a vulnerability, is an area that requires careful scrutiny to ensure the target endpoint is secure and the data sent is sanitized.

The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of secure development and maintenance. In conclusion, mosparo-integration v1.16.0 is a relatively secure plugin, with its strengths lying in its limited attack surface and good SQL and output handling. The single unsanitized path identified in the taint analysis is the primary area for concern and warrants further investigation to confirm its exploitability.

Key Concerns

  • Flow with unsanitized path
  • External HTTP requests made
  • Output escaping is not 100%
Vulnerabilities
None known

mosparo Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

mosparo Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
146 escaped
Nonce Checks
3
Capability Checks
2
File Operations
7
External Requests
1
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

76% escaped191 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
displayAdminNotice (src\MosparoIntegration\Helper\AdminHelper.php:464)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

mosparo Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 69
actionafter_setup_thememosparo-integration.php:43
actionafter_setup_thememosparo-integration.php:51
actionplugins_loadedmosparo-integration.php:59
actioninitmosparo-integration.php:65
actionadmin_enqueue_scriptssrc\MosparoIntegration\Helper\AdminHelper.php:54
actionnetwork_admin_menusrc\MosparoIntegration\Helper\AdminHelper.php:70
actionadmin_menusrc\MosparoIntegration\Helper\AdminHelper.php:72
actionmosparo_integration_refresh_css_url_cachesrc\MosparoIntegration\Helper\FrontendHelper.php:36
actionlogin_headsrc\MosparoIntegration\Module\Account\AccountModule.php:49
actionlogin_formsrc\MosparoIntegration\Module\Account\AccountModule.php:57
filterwp_authenticate_usersrc\MosparoIntegration\Module\Account\AccountModule.php:58
actionregister_formsrc\MosparoIntegration\Module\Account\AccountModule.php:63
filterregistration_errorssrc\MosparoIntegration\Module\Account\AccountModule.php:64
actionlostpassword_formsrc\MosparoIntegration\Module\Account\AccountModule.php:69
actionlostpassword_postsrc\MosparoIntegration\Module\Account\AccountModule.php:70
actioncomment_form_after_fieldssrc\MosparoIntegration\Module\Comments\CommentForm.php:28
filterpre_comment_approvedsrc\MosparoIntegration\Module\Comments\CommentForm.php:29
actionwpcf7_initsrc\MosparoIntegration\Module\ContactForm7\MosparoField.php:32
filterwpcf7_spamsrc\MosparoIntegration\Module\ContactForm7\MosparoField.php:33
actionwpcf7_admin_initsrc\MosparoIntegration\Module\ContactForm7\MosparoField.php:34
actionwpcf7_posted_data_selectsrc\MosparoIntegration\Module\ContactForm7\MosparoField.php:37
actionwpcf7_posted_data_select*src\MosparoIntegration\Module\ContactForm7\MosparoField.php:38
filteret_core_get_third_party_componentssrc\MosparoIntegration\Module\Divi\DiviModule.php:27
filteroption_et_core_api_spam_optionssrc\MosparoIntegration\Module\Divi\MosparoSpamServiceProvider.php:38
filteret_pb_contact_form_shortcode_outputsrc\MosparoIntegration\Module\Divi\MosparoSpamServiceProvider.php:39
filteret_pb_module_shortcode_attributessrc\MosparoIntegration\Module\Divi\MosparoSpamServiceProvider.php:40
actionwp_enqueue_scriptssrc\MosparoIntegration\Module\Divi\MosparoSpamServiceProvider.php:43
filteret_builder_plugin_stylesheet_contentssrc\MosparoIntegration\Module\Divi\MosparoSpamServiceProvider.php:46
actionwp_print_stylessrc\MosparoIntegration\Module\Divi\MosparoSpamServiceProvider.php:47
actionelementor/initsrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:34
actionelementor/preview/enqueue_scriptssrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:35
actionelementor/editor/after_enqueue_scriptssrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:36
filterelementor_pro/forms/field_typessrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:41
actionelementor_pro/forms/register/actionsrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:42
actionelementor/element/form/section_form_fields/before_section_endsrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:43
actionelementor_pro/forms/render/itemsrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:44
actionelementor_pro/forms/render_field/mosparosrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:45
filterelementor_pro/editor/localize_settingssrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:46
actionelementor_pro/forms/validationsrc\MosparoIntegration\Module\ElementorForm\MosparoField.php:47
filtereverest_forms_fieldssrc\MosparoIntegration\Module\EverestForms\EverestFormsModule.php:27
actionwp_enqueue_scriptssrc\MosparoIntegration\Module\EverestForms\EverestFormsModule.php:29
filterfrm_available_fieldssrc\MosparoIntegration\Module\Formidable\FormidableModule.php:29
filterfrm_get_field_type_classsrc\MosparoIntegration\Module\Formidable\FormidableModule.php:30
filterfrm_validate_entrysrc\MosparoIntegration\Module\Formidable\FormidableModule.php:31
filterforminator_render_form_submit_markupsrc\MosparoIntegration\Module\Forminator\ForminatorModule.php:58
filterforminator_spam_protectionsrc\MosparoIntegration\Module\Forminator\ForminatorModule.php:59
filterjet-form-builder/captcha/typessrc\MosparoIntegration\Module\JetFormBuilder\JetFormBuilderModule.php:27
actionmepr-before-login-formsrc\MosparoIntegration\Module\MemberpressAccount\MemberpressAccountModule.php:47
actionmepr-login-form-before-submitsrc\MosparoIntegration\Module\MemberpressAccount\MemberpressAccountModule.php:55
filtermepr-validate-loginsrc\MosparoIntegration\Module\MemberpressAccount\MemberpressAccountModule.php:56
actionmepr-forgot-password-formsrc\MosparoIntegration\Module\MemberpressAccount\MemberpressAccountModule.php:61
filtermepr-validate-forgot-passwordsrc\MosparoIntegration\Module\MemberpressAccount\MemberpressAccountModule.php:62
filternf_sub_hidden_field_typessrc\MosparoIntegration\Module\NinjaForms\MosparoField.php:60
filterninja_forms_field_template_file_pathssrc\MosparoIntegration\Module\NinjaForms\NinjaFormsModule.php:39
actionninja_forms_enqueue_scriptssrc\MosparoIntegration\Module\NinjaForms\NinjaFormsModule.php:44
filterninja_forms_register_fieldssrc\MosparoIntegration\Module\NinjaForms\NinjaFormsModule.php:53
filterninja_forms_register_actionssrc\MosparoIntegration\Module\NinjaForms\NinjaFormsModule.php:58
actionlogin_headsrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:74
actionwoocommerce_login_formsrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:82
filterwp_authenticate_usersrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:83
actionwoocommerce_register_formsrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:88
filterwoocommerce_process_registration_errorssrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:89
actionwoocommerce_lostpassword_formsrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:94
filterlostpassword_postsrc\MosparoIntegration\Module\WooCommerceAccount\WooCommerceAccountModule.php:95
actionwpforms_processsrc\MosparoIntegration\Module\WPForms\MosparoField.php:19
filterwsf_config_field_typessrc\MosparoIntegration\Module\WSForm\WSFormModule.php:32
filterwsf_config_meta_keyssrc\MosparoIntegration\Module\WSForm\WSFormModule.php:33
actionwsf_form_pre_process_fieldsrc\MosparoIntegration\Module\WSForm\WSFormModule.php:35
filterwsf_submit_validatesrc\MosparoIntegration\Module\WSForm\WSFormModule.php:37

Scheduled Events 1

mosparo_integration_refresh_css_url_cache
Maintenance & Trust

mosparo Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 21, 2026
PHP min version7.4
Downloads14K

Community Trust

Rating100/100
Number of ratings5
Active installs700
Developer Profile

mosparo Integration Developer Profile

mosparo

1 plugin · 700 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect mosparo Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mosparo-integration/assets/css/mosparo-admin.css/wp-content/plugins/mosparo-integration/assets/js/mosparo-admin.js
Script Paths
/wp-content/plugins/mosparo-integration/assets/js/mosparo-admin.js
Version Parameters
mosparo-integration/assets/css/mosparo-admin.css?ver=1.0mosparo-integration/assets/js/mosparo-admin.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
mosparo-integration-settingsmosparo-connection-form
Data Attributes
data-mosparo-auto-detect
JS Globals
window.mosparowindow.mosparoSettings
Shortcode Output
[mosparo-form]
FAQ

Frequently Asked Questions about mosparo Integration