
PowerLink CRM for Elementor Security & Risk Analysis
wordpress.org/plugins/powerlink-crm-for-elementorNew action after submission for elementor builder form widget. addon which adds new subscriber to Fireberry (Powerlink CRM) after form submission.
Is PowerLink CRM for Elementor Safe to Use in 2026?
Generally Safe
Score 85/100PowerLink CRM for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'powerlink-crm-for-elementor' v1.0.0 reveals a generally positive security posture, with no identified dangerous functions, SQL injection vulnerabilities due to prepared statements, or critical taint flows. The plugin also exhibits no known historical vulnerabilities, suggesting a strong commitment to security from the developers. However, there are several areas for improvement. The absence of nonce checks and capability checks on any entry points, combined with a complete lack of these checks on the discovered AJAX handlers and REST API routes, is a significant concern, creating a broad attack surface for unauthorized actions. Furthermore, only 67% of output is properly escaped, leaving a portion potentially vulnerable to cross-site scripting (XSS) attacks. The presence of file operations and external HTTP requests, while not inherently malicious, necessitates careful scrutiny for proper sanitization and authentication to prevent abuse.
While the plugin benefits from strong SQL practices and a clean vulnerability history, the identified weaknesses in authentication and output escaping, along with the bundling of Freemius v1.0 which may itself have undiscovered vulnerabilities or be outdated, present tangible risks. The lack of any identified entry points without authentication is misleading given the absence of checks on the existing ones. A balanced view indicates a plugin with good foundational security in some areas but critical oversights in others that could be exploited by attackers. Prioritizing the implementation of proper nonce and capability checks on all entry points, and addressing the unescaped output, is crucial for enhancing its security.
Key Concerns
- Missing nonce checks on AJAX/REST API
- Missing capability checks on AJAX/REST API
- Unescaped output (33%)
- Bundled Freemius v1.0 library
PowerLink CRM for Elementor Security Vulnerabilities
PowerLink CRM for Elementor Code Analysis
Bundled Libraries
Output Escaping
PowerLink CRM for Elementor Attack Surface
WordPress Hooks 3
Maintenance & Trust
PowerLink CRM for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
PowerLink CRM for Elementor Alternatives
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-dynamics-crm
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to dynamics crm Online.
GB To Powerlink
gb-powerlink-lite
GB To Powerlink allows Fireberry CRM (formerly known as PowerLink) users to easily integrate Contact Form 7 with their Fireberry CRM.
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-hubspot-crm
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with HubSpot CRM.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
PowerLink CRM for Elementor Developer Profile
6 plugins · 6K total installs
How We Detect PowerLink CRM for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
powerlink-crm-for-elementor/style.css?ver=powerlink-crm-for-elementor/script.js?ver=HTML / DOM Fingerprints
powerlink-crmRetrieve this value with:Array of All OptionsToken IDid="token_id_0"