PowerLink CRM for Elementor Security & Risk Analysis

wordpress.org/plugins/powerlink-crm-for-elementor

New action after submission for elementor builder form widget. addon which adds new subscriber to Fireberry (Powerlink CRM) after form submission.

20 active installs v1.0.0 PHP 5.6+ WP 5.0.0+ Updated Oct 28, 2022
contact-formcrmelementor-formfireberrypowerlink
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PowerLink CRM for Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

PowerLink CRM for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of 'powerlink-crm-for-elementor' v1.0.0 reveals a generally positive security posture, with no identified dangerous functions, SQL injection vulnerabilities due to prepared statements, or critical taint flows. The plugin also exhibits no known historical vulnerabilities, suggesting a strong commitment to security from the developers. However, there are several areas for improvement. The absence of nonce checks and capability checks on any entry points, combined with a complete lack of these checks on the discovered AJAX handlers and REST API routes, is a significant concern, creating a broad attack surface for unauthorized actions. Furthermore, only 67% of output is properly escaped, leaving a portion potentially vulnerable to cross-site scripting (XSS) attacks. The presence of file operations and external HTTP requests, while not inherently malicious, necessitates careful scrutiny for proper sanitization and authentication to prevent abuse.

While the plugin benefits from strong SQL practices and a clean vulnerability history, the identified weaknesses in authentication and output escaping, along with the bundling of Freemius v1.0 which may itself have undiscovered vulnerabilities or be outdated, present tangible risks. The lack of any identified entry points without authentication is misleading given the absence of checks on the existing ones. A balanced view indicates a plugin with good foundational security in some areas but critical oversights in others that could be exploited by attackers. Prioritizing the implementation of proper nonce and capability checks on all entry points, and addressing the unescaped output, is crucial for enhancing its security.

Key Concerns

  • Missing nonce checks on AJAX/REST API
  • Missing capability checks on AJAX/REST API
  • Unescaped output (33%)
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

PowerLink CRM for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PowerLink CRM for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

67% escaped3 total outputs
Attack Surface

PowerLink CRM for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuadmin\admin_powerlink.php:12
actionadmin_initadmin\admin_powerlink.php:13
actionelementor_pro/forms/actions/registerelementor-forms-powerlink-action.php:82
Maintenance & Trust

PowerLink CRM for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 28, 2022
PHP min version5.6
Downloads804

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

PowerLink CRM for Elementor Developer Profile

Ido Navarro

6 plugins · 6K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PowerLink CRM for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
powerlink-crm-for-elementor/style.css?ver=powerlink-crm-for-elementor/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
powerlink-crm
HTML Comments
Retrieve this value with:Array of All OptionsToken ID
Data Attributes
id="token_id_0"
FAQ

Frequently Asked Questions about PowerLink CRM for Elementor