
mosparo Integration Security & Risk Analysis
wordpress.org/plugins/mosparo-integrationThe plugin adds the functionality to use mosparo in WordPress forms or forms from Contact Form 7, Everest Form, and other plugins.
Is mosparo Integration Safe to Use in 2026?
Generally Safe
Score 100/100mosparo Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mosparo-integration plugin version 1.16.0 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, and shortcodes with any attack surface significantly reduces the potential for direct exploitation. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing a decent percentage of output escaping. The presence of nonce and capability checks also indicates an awareness of common WordPress security vulnerabilities.
However, a concern arises from the taint analysis, which identified one flow with an unsanitized path. While not classified as critical or high severity, this could indicate a potential vulnerability if this path is user-controllable and leads to sensitive operations or information disclosure. The plugin also makes one external HTTP request, which, while not inherently a vulnerability, is an area that requires careful scrutiny to ensure the target endpoint is secure and the data sent is sanitized.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of secure development and maintenance. In conclusion, mosparo-integration v1.16.0 is a relatively secure plugin, with its strengths lying in its limited attack surface and good SQL and output handling. The single unsanitized path identified in the taint analysis is the primary area for concern and warrants further investigation to confirm its exploitability.
Key Concerns
- Flow with unsanitized path
- External HTTP requests made
- Output escaping is not 100%
mosparo Integration Security Vulnerabilities
mosparo Integration Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
mosparo Integration Attack Surface
WordPress Hooks 69
Scheduled Events 1
Maintenance & Trust
mosparo Integration Maintenance & Trust
Maintenance Signals
Community Trust
mosparo Integration Alternatives
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
RD Station
integracao-rd-station
Integrate your contact forms with RD Station Marketing
GSheetConnector For WPForms – WPForms Google Sheets Integration (Real-Time Sync)
gsheetconnector-wpforms
Connect WPForms to Google Sheets and automatically send form entries to a google sheet in real-time. No manual exports, no coding required.
Fluent Forms Connector for MailPoet
fluent-forms-connector-for-mailpoet
Connect Fluent Forms with MailPoet.
Stop Contact Form 7 Spam & WPForms Spam – Free Protection
fullworks-anti-spam
Stop Contact Form 7 spam and WPForms spam instantly. Free spam protection for business sites. No CAPTCHA. No API keys. Just works.
mosparo Integration Developer Profile
1 plugin · 700 total installs
How We Detect mosparo Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mosparo-integration/assets/css/mosparo-admin.css/wp-content/plugins/mosparo-integration/assets/js/mosparo-admin.js/wp-content/plugins/mosparo-integration/assets/js/mosparo-admin.jsmosparo-integration/assets/css/mosparo-admin.css?ver=1.0mosparo-integration/assets/js/mosparo-admin.js?ver=1.0HTML / DOM Fingerprints
mosparo-integration-settingsmosparo-connection-formdata-mosparo-auto-detectwindow.mosparowindow.mosparoSettings[mosparo-form]