
Surbma | SalesAutopilot Shortcode Security & Risk Analysis
wordpress.org/plugins/surbma-salesautopilot-shortcodeA simple shortcode to include SalesAutopilot forms into WordPress.
Is Surbma | SalesAutopilot Shortcode Safe to Use in 2026?
Mostly Safe
Score 71/100Surbma | SalesAutopilot Shortcode is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "surbma-salesautopilot-shortcode" v2.5 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals an absence of dangerous functions, file operations, external HTTP requests, and all identified SQL queries utilize prepared statements. Output appears to be properly escaped, and the attack surface, while present via shortcodes, is minimal with no identified unauthenticated entry points. However, the plugin's vulnerability history is a significant concern, with one known medium-severity Cross-Site Scripting (XSS) vulnerability that remains unpatched. This indicates a historical tendency for insecure handling of input that can lead to XSS, and the fact that it is currently unpatched means this risk is actively exploitable.
Despite good practices in code sanitization and query preparation observed in the static analysis, the presence of an unpatched medium-severity XSS vulnerability overshadows these strengths. The lack of reported taint flows and dangerous functions is encouraging, but it's crucial to understand that static analysis alone may not catch all subtle vulnerabilities, especially those dependent on specific user interactions or configurations. The plugin's sole known vulnerability type being XSS is a red flag, suggesting potential weaknesses in how user-supplied data is rendered within the WordPress environment. Therefore, while the current codebase might appear clean in static analysis, the historical vulnerability necessitates caution and immediate attention to patching.
Key Concerns
- Unpatched CVE (medium severity)
Surbma | SalesAutopilot Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Surbma | SalesAutopilot Shortcode <= 2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Surbma | SalesAutopilot Shortcode Code Analysis
Output Escaping
Surbma | SalesAutopilot Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Surbma | SalesAutopilot Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | SalesAutopilot Shortcode Alternatives
Forms Shortcode for BeaconCRM (community)
forms-shortcode-for-beaconcrm
Easily embed BeaconCRM forms into WordPress using a simple shortcode.
LOYA.ID Easy Lead Form
loya-id-easy-lead-form
Easily add a lead form to your WordPress site that integrates with the LOYA.ID CRM using a shortcode. Ideal for capturing leads with global phone supp …
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
YITH WooCommerce Ajax Search
yith-woocommerce-ajax-search
YITH WooCommerce Ajax Search allows your users to search products in real time.
Surbma | SalesAutopilot Shortcode Developer Profile
27 plugins · 30K total installs
How We Detect Surbma | SalesAutopilot Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://d1ursyhqs5x9h1.cloudfront.net/sw/scripts/embed-iframe-form.jsHTML / DOM Fingerprints
<div style="width: [value]"><script type="text/javascript" src="https://d1ursyhqs5x9h1.cloudfront.net/sw/scripts/embed-iframe-form.js?listId=[value]&formId=[value]"></script></div>