Surbma | SalesAutopilot Shortcode Security & Risk Analysis

wordpress.org/plugins/surbma-salesautopilot-shortcode

A simple shortcode to include SalesAutopilot forms into WordPress.

100 active installs v2.5 PHP 7.4+ WP 5.1+ Updated Dec 30, 2024
crmformsalesautopilotshortcode
71
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 11, 2024
Safety Verdict

Is Surbma | SalesAutopilot Shortcode Safe to Use in 2026?

Mostly Safe

Score 71/100

Surbma | SalesAutopilot Shortcode is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 11, 2024Updated 1yr ago
Risk Assessment

The "surbma-salesautopilot-shortcode" v2.5 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals an absence of dangerous functions, file operations, external HTTP requests, and all identified SQL queries utilize prepared statements. Output appears to be properly escaped, and the attack surface, while present via shortcodes, is minimal with no identified unauthenticated entry points. However, the plugin's vulnerability history is a significant concern, with one known medium-severity Cross-Site Scripting (XSS) vulnerability that remains unpatched. This indicates a historical tendency for insecure handling of input that can lead to XSS, and the fact that it is currently unpatched means this risk is actively exploitable.

Despite good practices in code sanitization and query preparation observed in the static analysis, the presence of an unpatched medium-severity XSS vulnerability overshadows these strengths. The lack of reported taint flows and dangerous functions is encouraging, but it's crucial to understand that static analysis alone may not catch all subtle vulnerabilities, especially those dependent on specific user interactions or configurations. The plugin's sole known vulnerability type being XSS is a red flag, suggesting potential weaknesses in how user-supplied data is rendered within the WordPress environment. Therefore, while the current codebase might appear clean in static analysis, the historical vulnerability necessitates caution and immediate attention to patching.

Key Concerns

  • Unpatched CVE (medium severity)
Vulnerabilities
1

Surbma | SalesAutopilot Shortcode Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11433medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Surbma | SalesAutopilot Shortcode <= 2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 11, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

Surbma | SalesAutopilot Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Surbma | SalesAutopilot Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[sa-form] surbma-salesautopilot-shortcode.php:27
WordPress Hooks 1
actioninitsurbma-salesautopilot-shortcode.php:23
Maintenance & Trust

Surbma | SalesAutopilot Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 30, 2024
PHP min version7.4
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Surbma | SalesAutopilot Shortcode Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | SalesAutopilot Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://d1ursyhqs5x9h1.cloudfront.net/sw/scripts/embed-iframe-form.js

HTML / DOM Fingerprints

Shortcode Output
<div style="width: [value]"><script type="text/javascript" src="https://d1ursyhqs5x9h1.cloudfront.net/sw/scripts/embed-iframe-form.js?listId=[value]&formId=[value]"></script></div>
FAQ

Frequently Asked Questions about Surbma | SalesAutopilot Shortcode