Wikimotive's Task Forms for ClickUp – Free Security & Risk Analysis

wordpress.org/plugins/wikimotive-clickup-task-forms-free

This plugin allows you to add Task Submission Forms for ClickUp to your Wordpress website via the use of shortcodes and ClickUp's Cloud API Conne …

20 active installs v1.0.1 PHP 7.0+ WP 4.9+ Updated Sep 1, 2020
api-integrationclickupformstask-management
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wikimotive's Task Forms for ClickUp – Free Safe to Use in 2026?

Generally Safe

Score 85/100

Wikimotive's Task Forms for ClickUp – Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The wikimotive-clickup-task-forms-free plugin, version 1.0.1, exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, critical taint flows, or dangerous functions is a significant positive indicator. The plugin also demonstrates good practices by consistently using prepared statements for all SQL queries and implementing a substantial number of capability checks (28), which helps in restricting access to sensitive functionalities. The limited attack surface, with only two shortcodes and no unprotected AJAX handlers or REST API routes, further contributes to its security. However, a notable area of concern is the output escaping, where only 65% of outputs are properly escaped. This leaves a significant portion of potentially user-influenced data vulnerable to cross-site scripting (XSS) attacks if not handled carefully by the surrounding WordPress environment or user input sanitization. Additionally, the plugin makes 8 external HTTP requests, which, while not inherently a vulnerability, introduces a dependency on external services and potential risks if those services are compromised or unavailable.

Key Concerns

  • 65% of outputs properly escaped
  • 8 external HTTP requests
Vulnerabilities
None known

Wikimotive's Task Forms for ClickUp – Free Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wikimotive's Task Forms for ClickUp – Free Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
108
202 escaped
Nonce Checks
10
Capability Checks
28
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

65% escaped310 total outputs
Attack Surface

Wikimotive's Task Forms for ClickUp – Free Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[ctf_form] public\partials\shortcode.php:25
[ctf_form] trunk\public\partials\shortcode.php:25
WordPress Hooks 78
actionadmin_initadmin\partials\admin-functions.php:21
actionadmin_menuadmin\partials\admin-menu.php:43
actionadmin_noticesadmin\partials\admin-messages.php:23
actionadd_meta_boxesadmin\partials\forms-cpt-fields.php:26
filterrwmb_meta_boxesadmin\partials\forms-cpt-fields.php:138
actionsave_postadmin\partials\forms-cpt-fields.php:315
actioninitadmin\partials\forms-post-type.php:62
actionadmin_initadmin\partials\setup-wizard.php:97
actionplugins_loadedincludes\class-clickup-task-forms.php:171
actionadmin_enqueue_scriptsincludes\class-clickup-task-forms.php:186
actionadmin_enqueue_scriptsincludes\class-clickup-task-forms.php:187
actionwp_enqueue_scriptsincludes\class-clickup-task-forms.php:202
actionwp_enqueue_scriptsincludes\class-clickup-task-forms.php:203
actioninitincludes\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileincludes\class-tgm-plugin-activation.php:269
actioninitincludes\class-tgm-plugin-activation.php:272
actionadmin_menuincludes\class-tgm-plugin-activation.php:421
actionadmin_headincludes\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:426
actionadmin_noticesincludes\class-tgm-plugin-activation.php:429
actionadmin_initincludes\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsincludes\class-tgm-plugin-activation.php:431
actionload-plugins.phpincludes\class-tgm-plugin-activation.php:436
actionswitch_themeincludes\class-tgm-plugin-activation.php:439
actionswitch_themeincludes\class-tgm-plugin-activation.php:442
actionadmin_initincludes\class-tgm-plugin-activation.php:447
actionswitch_themeincludes\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileincludes\class-tgm-plugin-activation.php:475
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:889
actionplugins_loadedincludes\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsincludes\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:2977
actionadmin_initincludes\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeincludes\class-tgm-plugin-activation.php:3242
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3301
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3446
actionwp_headerspublic\partials\shortcode.php:16
actionadmin_inittrunk\admin\partials\admin-functions.php:21
actionadmin_menutrunk\admin\partials\admin-menu.php:43
actionadmin_noticestrunk\admin\partials\admin-messages.php:23
actionadd_meta_boxestrunk\admin\partials\forms-cpt-fields.php:26
filterrwmb_meta_boxestrunk\admin\partials\forms-cpt-fields.php:138
actionsave_posttrunk\admin\partials\forms-cpt-fields.php:315
actioninittrunk\admin\partials\forms-post-type.php:62
actionadmin_inittrunk\admin\partials\setup-wizard.php:97
actionplugins_loadedtrunk\includes\class-clickup-task-forms.php:171
actionadmin_enqueue_scriptstrunk\includes\class-clickup-task-forms.php:186
actionadmin_enqueue_scriptstrunk\includes\class-clickup-task-forms.php:187
actionwp_enqueue_scriptstrunk\includes\class-clickup-task-forms.php:202
actionwp_enqueue_scriptstrunk\includes\class-clickup-task-forms.php:203
actioninittrunk\includes\class-tgm-plugin-activation.php:268
filterload_textdomain_mofiletrunk\includes\class-tgm-plugin-activation.php:269
actioninittrunk\includes\class-tgm-plugin-activation.php:272
actionadmin_menutrunk\includes\class-tgm-plugin-activation.php:421
actionadmin_headtrunk\includes\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionstrunk\includes\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionstrunk\includes\class-tgm-plugin-activation.php:426
actionadmin_noticestrunk\includes\class-tgm-plugin-activation.php:429
actionadmin_inittrunk\includes\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptstrunk\includes\class-tgm-plugin-activation.php:431
actionload-plugins.phptrunk\includes\class-tgm-plugin-activation.php:436
actionswitch_themetrunk\includes\class-tgm-plugin-activation.php:439
actionswitch_themetrunk\includes\class-tgm-plugin-activation.php:442
actionadmin_inittrunk\includes\class-tgm-plugin-activation.php:447
actionswitch_themetrunk\includes\class-tgm-plugin-activation.php:452
actionload_textdomain_mofiletrunk\includes\class-tgm-plugin-activation.php:475
filterupgrader_source_selectiontrunk\includes\class-tgm-plugin-activation.php:889
actionplugins_loadedtrunk\includes\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemstrunk\includes\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectiontrunk\includes\class-tgm-plugin-activation.php:2977
actionadmin_inittrunk\includes\class-tgm-plugin-activation.php:3147
actionupgrader_process_completetrunk\includes\class-tgm-plugin-activation.php:3242
filterupgrader_post_installtrunk\includes\class-tgm-plugin-activation.php:3301
filterupgrader_post_installtrunk\includes\class-tgm-plugin-activation.php:3446
actionwp_headerstrunk\public\partials\shortcode.php:16
actiontgmpa_registertrunk\wikimotive-clickup-task-forms-free.php:133
actiontgmpa_registerwikimotive-clickup-task-forms-free.php:133
Maintenance & Trust

Wikimotive's Task Forms for ClickUp – Free Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedSep 1, 2020
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Wikimotive's Task Forms for ClickUp – Free Developer Profile

wikimotivedev

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wikimotive's Task Forms for ClickUp – Free

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/css/admin.css/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/js/admin.js/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/css/frontend.css/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/js/frontend.js
Script Paths
/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/js/admin.js/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/js/frontend.js
Version Parameters
/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/css/admin.css?ver=/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/js/admin.js?ver=/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/css/frontend.css?ver=/wp-content/plugins/wikimotive-clickup-task-forms-free/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ctf-admin-settings-pagectf-admin-settings-wrapctf-admin-setting-fieldctf-frontend-form-wrapper
Data Attributes
data-ctf-form-iddata-ctf-clickup-list-iddata-ctf-clickup-task-template-id
JS Globals
CTF_AJAX_OBJECT
Shortcode Output
[wikimotive_clickup_task_form]
FAQ

Frequently Asked Questions about Wikimotive's Task Forms for ClickUp – Free