
WorkZen Connector Security & Risk Analysis
wordpress.org/plugins/workzen-connectorConnect your WordPress forms to WorkZen CRM and never miss a lead again.
Is WorkZen Connector Safe to Use in 2026?
Generally Safe
Score 100/100WorkZen Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Workzen Connector plugin, version 1.12.3, exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of unprotected entry points (AJAX, REST API). All identified AJAX handlers and REST API routes appear to have appropriate authentication and permission checks, which is a critical security best practice. Furthermore, the plugin demonstrates excellent SQL query security, utilizing prepared statements for 100% of its database interactions, effectively mitigating SQL injection risks. The high percentage of properly escaped output (97%) is also commendable, reducing the likelihood of cross-site scripting (XSS) vulnerabilities. Despite these strengths, there are minor areas for attention. The presence of 6 instances of 'preg_replace(/e)' is a signal for potential security concerns, as this specific regex modifier can sometimes lead to unintended behavior or vulnerabilities if not handled with extreme care. While taint analysis shows no reported issues, this function warrants closer scrutiny in a dynamic analysis. The plugin's vulnerability history is clean, with no known CVEs, which is a very positive indicator of past security diligence. However, the absence of historical vulnerabilities does not guarantee future security, and the 'preg_replace(/e)' calls represent a potential, albeit unproven, weakness that could be exploited if not properly mitigated.
Key Concerns
- Presence of 'preg_replace(/e)'
WorkZen Connector Security Vulnerabilities
WorkZen Connector Code Analysis
Dangerous Functions Found
Output Escaping
WorkZen Connector Attack Surface
AJAX Handlers 13
Shortcodes 5
WordPress Hooks 28
Scheduled Events 3
Maintenance & Trust
WorkZen Connector Maintenance & Trust
Maintenance Signals
Community Trust
WorkZen Connector Alternatives
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-dynamics-crm
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to dynamics crm Online.
Juridic-OS Connector
juridic-os-connector
El plugin oficial de Juridic-OS para integración de formularios de contacto con sistemas de gestión legal.
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Contact Form to Any API
contact-form-to-any-api
Send Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
WorkZen Connector Developer Profile
1 plugin · 0 total installs
How We Detect WorkZen Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/workzen-connector/assets/js/wzc-admin-scripts.js/wp-content/plugins/workzen-connector/assets/css/wzc-admin-styles.css/wp-content/plugins/workzen-connector/assets/js/wzc-frontend-scripts.js/wp-content/plugins/workzen-connector/assets/css/wzc-frontend-styles.css/wp-content/plugins/workzen-connector/assets/images/workzen-sloth-icon.svg/wp-content/plugins/workzen-connector/assets/js/wzc-admin-scripts.js/wp-content/plugins/workzen-connector/assets/js/wzc-frontend-scripts.jsworkzen-connector/assets/js/wzc-admin-scripts.js?ver=workzen-connector/assets/css/wzc-admin-styles.css?ver=workzen-connector/assets/js/wzc-frontend-scripts.js?ver=workzen-connector/assets/css/wzc-frontend-styles.css?ver=HTML / DOM Fingerprints
wzc-admin-settings-pagewzc-queue-tablewzc-integration-list-itemwzc-lead-form-wrapperwzc-floating-button<!-- WorkZen Connector Settings Page --><!-- WorkZen Connector Queue Table --><!-- End WorkZen Connector Queue Table --><!-- Floating WorkZen Button -->+1 moredata-workzen-endpointdata-workzen-integration-keydata-wzc-form-idwindow.WZC_Adminwindow.WZC_Frontendvar wzc_ajax_object/wp-json/workzen-connector/v1/settings/wp-json/workzen-connector/v1/send-lead<div class="workzen-connector-shortcode"><a href="#" class="wzc-book-appointment-button">Book Appointment</a></div>