
NeonCRM Sign-In Security & Risk Analysis
wordpress.org/plugins/neoncrm-sign-inSign in to WordPress using a NeonCRM constituent account.
Is NeonCRM Sign-In Safe to Use in 2026?
Generally Safe
Score 85/100NeonCRM Sign-In has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "neoncrm-sign-in" plugin v1.2.0 exhibits a generally good security posture based on the provided static analysis. The absence of critical or high-severity taint flows and the consistent use of prepared statements for SQL queries are positive indicators. Additionally, the plugin's limited attack surface, with no unprotected AJAX handlers or REST API routes, further enhances its security. However, there are a couple of areas that warrant attention. While the plugin has a clean vulnerability history with no known CVEs, this does not guarantee future safety and should be monitored. The presence of external HTTP requests (6 total) without further context on their purpose and implementation could introduce risks if not handled securely. Furthermore, the lack of explicit nonce checks, coupled with the fact that there are no recorded capability checks on the identified entry points (shortcodes), represents a potential weakness for ensuring legitimate user actions.
Key Concerns
- 0 Nonce checks on entry points
- 6 External HTTP requests without context
- 2 Shortcodes without capability checks
NeonCRM Sign-In Security Vulnerabilities
NeonCRM Sign-In Code Analysis
Output Escaping
NeonCRM Sign-In Attack Surface
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
NeonCRM Sign-In Maintenance & Trust
Maintenance Signals
Community Trust
NeonCRM Sign-In Alternatives
NeonCRM Events Widget
neoncrm-events-widget
Displays a feed of upcoming events retrieved from NeonCRM.
CiviEvent Widget
civievent-widget
Display widgets for CiviCRM events: the next public event or a whole list. Embed widgets as shortcodes, too!
Office 365 User Authentication for WordPress
o365-user-authentication
Authenticate and log in WordPress users securely with Office 365 / Azure Active Directory single sign-on.
Flamingo
flamingo
A trustworthy message storage plugin for Contact Form 7.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
NeonCRM Sign-In Developer Profile
2 plugins · 70 total installs
How We Detect NeonCRM Sign-In
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/neoncrm-sign-in/css/neoncrm-sso-styles.css/wp-content/plugins/neoncrm-sign-in/js/neoncrm-sso-script.js/wp-content/plugins/neoncrm-sign-in/js/neoncrm-sso-script.jsneoncrm-sign-in/css/neoncrm-sso-styles.css?ver=neoncrm-sign-in/js/neoncrm-sso-script.js?ver=HTML / DOM Fingerprints
neonsso-login-button<a href="