Privyr CRM – Instant Lead Alerts for Contact Forms Security & Risk Analysis

wordpress.org/plugins/privy-crm-integration

Get instant new lead alerts on your phone and via email, combined with easy lead management and one-touch calls, WhatsApp, SMS, iMessage, and emails.

4K active installs v1.0.3 PHP 5.6+ WP 5.0+ Updated Apr 16, 2025
elementorgravityprivyrwpcf7wpforms
91
A · Safe
CVEs total1
Unpatched0
Last CVEApr 4, 2025
Safety Verdict

Is Privyr CRM – Instant Lead Alerts for Contact Forms Safe to Use in 2026?

Generally Safe

Score 91/100

Privyr CRM – Instant Lead Alerts for Contact Forms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 4, 2025Updated 1yr ago
Risk Assessment

The privy-crm-integration plugin version 1.0.3 exhibits a mixed security posture. While static analysis shows a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events without authorization checks, and a complete absence of dangerous functions, file operations, and critical taint flows, there are notable areas of concern. The plugin uses raw SQL queries without prepared statements, which presents a significant risk for SQL injection vulnerabilities if the input data is not meticulously sanitized elsewhere. Furthermore, only 50% of output operations are properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. The presence of a past medium severity CVE, specifically a "Missing Authorization" type, is a significant red flag, even if currently unpatched. This history suggests a pattern of security oversights that could be reintroduced or remain undiscovered in current code. While the lack of active unpatched CVEs and the current low attack surface are positive, the underlying code quality, evidenced by the SQL and output escaping issues and the historical vulnerability, warrants careful consideration and ongoing monitoring.

Key Concerns

  • Raw SQL queries without prepared statements
  • Half of output operations are not properly escaped
  • Past medium CVE for Missing Authorization
Vulnerabilities
1 published

Privyr CRM – Instant Lead Alerts for Contact Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32224medium · 4.3Missing Authorization

Privyr CRM <= 1.0.2 - Missing Authorization

Apr 4, 2025 Patched in 1.0.3 (14d)
Version History

Privyr CRM – Instant Lead Alerts for Contact Forms Release Timeline

v1.0.3Current
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
v0.7.21 CVE
v0.7.11 CVE
vV0.71 CVE
v0.51 CVE
v0.41 CVE
v0.3.11 CVE
v0.31 CVE
vv0.2.11 CVE
v0.2.01 CVE
v0.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Privyr CRM – Instant Lead Alerts for Contact Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

50% escaped2 total outputs
Attack Surface

Privyr CRM – Instant Lead Alerts for Contact Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_enqueue_scriptsincludes\class-privyr-crm.php:166
actionadmin_enqueue_scriptsincludes\class-privyr-crm.php:167
actionadmin_menuincludes\class-privyr-crm.php:168
actionwpcf7_before_send_mailincludes\class-privyr-crm.php:194
actionwpforms_process_completeincludes\class-privyr-crm.php:201
actionelementor_pro/forms/new_recordincludes\class-privyr-crm.php:208
actiongform_after_submissionincludes\class-privyr-crm.php:215
actionhouzez_after_agent_form_submissionincludes\class-privyr-crm.php:222
actionhouzez_after_contact_form_submissionincludes\class-privyr-crm.php:223
actionhouzez_after_estimation_form_submissionincludes\class-privyr-crm.php:224
actionet_pb_contact_form_submitincludes\class-privyr-crm.php:231
actionninja_forms_after_submissionincludes\class-privyr-crm.php:239
actionforminator_form_after_save_entryincludes\class-privyr-crm.php:249
actionfluentform_submission_insertedincludes\class-privyr-crm.php:256
actionfrm_after_create_entryincludes\class-privyr-crm.php:263
actioneverest_forms_complete_entry_saveincludes\class-privyr-crm.php:270
actionmetform_after_store_form_dataincludes\class-privyr-crm.php:277
Maintenance & Trust

Privyr CRM – Instant Lead Alerts for Contact Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 16, 2025
PHP min version5.6
Downloads32K

Community Trust

Rating100/100
Number of ratings1
Active installs4K
Developer Profile

Privyr CRM – Instant Lead Alerts for Contact Forms Developer Profile

Shivam Mani Tripathi

1 plugin · 4K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Privyr CRM – Instant Lead Alerts for Contact Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/privy-crm-integration/admin/css/libs/tailwind.min.css/wp-content/plugins/privy-crm-integration/admin/js/libs/petite-vue.min.js
Version Parameters
privy-crm-integration/admin/css/libs/tailwind.min.css?ver=privy-crm-integration/admin/js/libs/petite-vue.min.js?ver=

HTML / DOM Fingerprints

JS Globals
petiteVue
FAQ

Frequently Asked Questions about Privyr CRM – Instant Lead Alerts for Contact Forms