
Account Engagement Security & Risk Analysis
wordpress.org/plugins/pardotIntegrate Account Engagement with WordPress: easily track visitors, embed forms and dynamic content in pages and posts, or use the forms or dynamic co …
Is Account Engagement Safe to Use in 2026?
Generally Safe
Score 92/100Account Engagement has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "pardot" plugin v2.1.2 exhibits a mixed security posture. While the static analysis shows a strong adherence to good practices in terms of entry point protection and the absence of dangerous functions, there are significant concerns regarding data handling and historical vulnerability patterns. The fact that 100% of SQL queries are not using prepared statements is a major red flag, indicating a high potential for SQL injection vulnerabilities. Furthermore, the taint analysis revealing two flows with unsanitized paths, even if not classified as critical or high severity, suggests potential for cross-site scripting (XSS) or other injection attacks if these paths are exploited.
The vulnerability history shows one known medium-severity CVE, which has since been patched. However, the common vulnerability type of "Missing Authorization" in the past is a worrying trend. This, combined with the current lack of explicit permission callbacks for REST API routes (though there are none listed) and the overall presence of unsanitized paths in taint flows, suggests a recurring weakness in how the plugin handles user input and controls access. The plugin does demonstrate strengths in its limited attack surface and the implementation of nonce and capability checks for its identified entry points.
In conclusion, while the "pardot" plugin has made efforts to secure its entry points and has patched past vulnerabilities, the absence of prepared statements for all SQL queries and the presence of unsanitized paths in taint flows represent critical areas of concern. The historical pattern of missing authorization vulnerabilities also warrants caution. Developers should prioritize addressing the SQL query security and thoroughly reviewing and sanitizing all data flows.
Key Concerns
- 100% of SQL queries not using prepared statements
- 2 taint flows with unsanitized paths
- 45% of output properly escaped
- Bundled outdated library: TinyMCE v1.0
- 1 past medium severity CVE (historical risk)
Account Engagement Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pardot <= 2.1.0 - Missing Authorization
Account Engagement Release Timeline
Account Engagement Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Account Engagement Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 23
Maintenance & Trust
Account Engagement Maintenance & Trust
Maintenance Signals
Community Trust
Account Engagement Alternatives
Zoho Campaigns
zoho-campaigns
Zoho Campaigns
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
cf7-salesforce
Send Contact Form 7, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submissions to salesforce.
ActiveDEMAND
activedemand
ActiveDEMAND, the easy way to add Web Forms, Dynamic Content, and Popups to your WordPress site.
Connector for Gravity Forms and Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
Object Data Sync for Salesforce Integration with WP, Woo, Gravity, WPForms, Ninja, CF7 & more
object-data-sync-for-salesforce
Integrate Salesforce with WordPress to map and sync WordPress data like users, posts, WooCommerce orders, forms, and events with Salesforce standard a …
Account Engagement Developer Profile
2 plugins · 2K total installs
How We Detect Account Engagement
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pardot/build/index.css/wp-content/plugins/pardot/build/index.js/wp-content/plugins/pardot/build/style-index.css/wp-content/plugins/pardot/css/popup.css/wp-content/plugins/pardot/js/popup.js//cdnjs.cloudflare.com/ajax/libs/chosen/1.1.0/chosen.min.css//cdnjs.cloudflare.com/ajax/libs/chosen/1.8.2/chosen.jquery.min.jspardot/build/index.js?ver=pardot/build/index.css?ver=pardot/build/style-index.css?ver=HTML / DOM Fingerprints
pardot-forms-shortcode-popupdata-pardot-formdata-pardot-dynamic-contentPardotShortcodePopup[pardot-form][pardot-form id=][pardot-form height=][pardot-form width=]