LeadLab by wiredminds Security & Risk Analysis

wordpress.org/plugins/wiredminds-leadlab

Integration of the Wiredminds LeadLab trackingcode.

100 active installs v1.4.3 PHP 7.4+ WP 4.8.1+ Updated Jul 11, 2025
leadlabtracking-codewebanalyserwiredminds
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 1, 2025
Safety Verdict

Is LeadLab by wiredminds Safe to Use in 2026?

Generally Safe

Score 99/100

LeadLab by wiredminds has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 1, 2025Updated 8mo ago
Risk Assessment

The wiredminds-leadlab plugin v1.4.3 demonstrates a generally strong security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the code signals indicate a responsible development approach, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The presence of nonce and capability checks further reinforces this positive assessment.

However, the plugin's vulnerability history raises a concern. The existence of one known CVE, even if currently unpatched and of medium severity, suggests that vulnerabilities have been discovered in the past. While the static analysis did not reveal any critical or high severity issues in the current version, the historical pattern of Cross-site Scripting (XSS) vulnerabilities implies a potential for undiscovered flaws or regressions. The lack of an identified attack surface is a positive sign for the current version, but the historical context warrants a cautious approach.

In conclusion, the wiredminds-leadlab plugin v1.4.3 appears to be well-developed with excellent security practices evident in its code. The static analysis reveals no immediate critical risks. Nevertheless, the past discovery of a medium-severity XSS vulnerability, though patched, indicates that diligent security monitoring and prompt updates are crucial for this plugin to maintain its security. Users should remain vigilant for future updates and advisories.

Key Concerns

  • 1 Medium Severity CVE historically
Vulnerabilities
1

LeadLab by wiredminds Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31568medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

LeadLab by wiredminds <= 1.3 - Reflected Cross-Site Scripting

Apr 1, 2025 Patched in 1.4 (102d)
Code Analysis
Analyzed Mar 16, 2026

LeadLab by wiredminds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
9 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped9 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wp_wm_handle_form_submission (leadlab.php:72)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LeadLab by wiredminds Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuleadlab.php:393
actionwp_footerleadlab.php:394
actionadmin_initleadlab.php:395
Maintenance & Trust

LeadLab by wiredminds Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJul 11, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

LeadLab by wiredminds Developer Profile

wiredmindshelp

3 plugins · 110 total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect LeadLab by wiredminds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wiredminds-leadlab/assets/js/script.js/wp-content/plugins/wiredminds-leadlab/assets/css/style.css
Script Paths
/wp-content/plugins/wiredminds-leadlab/assets/js/script.js
Version Parameters
wiredminds-leadlab/assets/js/script.js?ver=wiredminds-leadlab/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-wm-formwp-wm-labelwp-wm-inputwp-wm-descriptionwp-wm-submitwp-wm-statuswp-wm-status activewp-wm-status inactive
HTML Comments
<!-- LeadLab tracking code --><!-- End LeadLab tracking code --><!-- BEGIN: wiredminds LeadLab tracking code --><!-- END: wiredminds LeadLab tracking code -->
Data Attributes
pattern="[a-zA-Z0-9]{16}"title="Geben Sie genau 16 alphanumerische Zeichen ein"oninput="this.value = this.value.replace(/[^a-zA-Z0-9]/g, '')"
JS Globals
window.wiredminds = window.wiredminds || {};window.wiredminds.leadlab = window.wiredminds.leadlab || {};window.wiredminds.leadlab.trackingId = '%%TRACKING_ID%%';
FAQ

Frequently Asked Questions about LeadLab by wiredminds