
VIA Lead Integration for Gravity Forms and Salesforce Security & Risk Analysis
wordpress.org/plugins/via-crm-formsVIA Lead Integration for Gravity Forms and Salesforce
Is VIA Lead Integration for Gravity Forms and Salesforce Safe to Use in 2026?
Generally Safe
Score 85/100VIA Lead Integration for Gravity Forms and Salesforce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'via-crm-forms' plugin, version 1.0.5, exhibits a mixed security posture. On the positive side, it demonstrates good practice by exclusively using prepared statements for its SQL queries and has no recorded vulnerability history, suggesting a generally stable codebase. The absence of critical or high-severity taint flows is also encouraging, indicating that the plugin is likely not introducing severe injection vulnerabilities based on the static analysis performed.
However, the plugin presents significant security concerns due to its attack surface. All three identified AJAX handlers lack authentication checks, creating a direct entry point for unauthenticated users to interact with sensitive functionalities. Furthermore, a concerning 60% of output operations are not properly escaped. This combination of unprotected entry points and insufficient output escaping significantly increases the risk of cross-site scripting (XSS) vulnerabilities and other injection attacks. The use of the Guzzle library also warrants attention; while not inherently a vulnerability, bundled libraries can become a risk if they are outdated and contain known vulnerabilities.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and historical vulnerabilities, the lack of authentication on AJAX handlers and the prevalence of unescaped output are critical weaknesses. These issues create a substantial risk that needs to be addressed to improve the plugin's overall security. The lack of historical CVEs is a positive indicator of past development but does not mitigate the immediate risks identified in the current version's static analysis.
Key Concerns
- AJAX handlers without authentication
- Insufficient output escaping (40% properly escaped)
- Bundled Guzzle library
VIA Lead Integration for Gravity Forms and Salesforce Security Vulnerabilities
VIA Lead Integration for Gravity Forms and Salesforce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
VIA Lead Integration for Gravity Forms and Salesforce Attack Surface
AJAX Handlers 3
WordPress Hooks 7
Maintenance & Trust
VIA Lead Integration for Gravity Forms and Salesforce Maintenance & Trust
Maintenance Signals
Community Trust
VIA Lead Integration for Gravity Forms and Salesforce Alternatives
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
FormsCRM – Connect Forms to CRM directly
formscrm
Connects your CRM, ERP and Email Marketing with your Forms plugin and create new Leads/Entries as the forms are filled automatically. GDPR compliant.
WP Gravity Forms Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
LeadSnap
leadsnap
Save the leads to our lead management system CRM generated by Contact Form 7
Object Sync for Salesforce
object-sync-for-salesforce
Object Sync for Salesforce maps and syncs data between Salesforce objects and WordPress objects.
VIA Lead Integration for Gravity Forms and Salesforce Developer Profile
2 plugins · 100 total installs
How We Detect VIA Lead Integration for Gravity Forms and Salesforce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/via-crm-forms/build/via-gravityforms.js/wp-content/plugins/via-crm-forms/build/via-gravityforms.css/wp-content/plugins/via-crm-forms/build/via-gravityforms.jsvia-crm-forms/via-gravityforms-salesforce.php?ver=via-gravityforms-salesforce/build/via-gravityforms.js?ver=via-gravityforms-salesforce/build/via-gravityforms.css?ver=HTML / DOM Fingerprints
viagf_invaliddata-gform-confirm-filtergf_salesforce_addon