WorkZen Connector Security & Risk Analysis

wordpress.org/plugins/workzen-connector

Connect your WordPress forms to WorkZen CRM and never miss a lead again.

0 active installs v1.12.3 PHP 7.4+ WP 5.0+ Updated Unknown
contact-form-7crmformsintegrationleads
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WorkZen Connector Safe to Use in 2026?

Generally Safe

Score 100/100

WorkZen Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The Workzen Connector plugin, version 1.12.3, exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of unprotected entry points (AJAX, REST API). All identified AJAX handlers and REST API routes appear to have appropriate authentication and permission checks, which is a critical security best practice. Furthermore, the plugin demonstrates excellent SQL query security, utilizing prepared statements for 100% of its database interactions, effectively mitigating SQL injection risks. The high percentage of properly escaped output (97%) is also commendable, reducing the likelihood of cross-site scripting (XSS) vulnerabilities. Despite these strengths, there are minor areas for attention. The presence of 6 instances of 'preg_replace(/e)' is a signal for potential security concerns, as this specific regex modifier can sometimes lead to unintended behavior or vulnerabilities if not handled with extreme care. While taint analysis shows no reported issues, this function warrants closer scrutiny in a dynamic analysis. The plugin's vulnerability history is clean, with no known CVEs, which is a very positive indicator of past security diligence. However, the absence of historical vulnerabilities does not guarantee future security, and the 'preg_replace(/e)' calls represent a potential, albeit unproven, weakness that could be exploited if not properly mitigated.

Key Concerns

  • Presence of 'preg_replace(/e)'
Vulnerabilities
None known

WorkZen Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WorkZen Connector Code Analysis

Dangerous Functions
6
Raw SQL Queries
0
0 prepared
Unescaped Output
17
490 escaped
Nonce Checks
14
Capability Checks
9
File Operations
1
External Requests
13
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '/\/eincludes\class-ajax-handlers.php:208
preg_replace(/e)preg_replace( '/\/eincludes\class-ajax-handlers.php:959
preg_replace(/e)preg_replace( '/\/eincludes\class-workzen-connector.php:268
preg_replace(/e)preg_replace( '/\/eincludes\class-workzen-connector.php:330
preg_replace(/e)preg_replace( '/\/eworkzen-connector.php:78
preg_replace(/e)preg_replace( '/\/eworkzen-connector.php:122

Output Escaping

97% escaped507 total outputs
Attack Surface

WorkZen Connector Attack Surface

Entry Points18
Unprotected0

AJAX Handlers 13

authwp_ajax_wzconnector_toggle_integrationincludes\class-ajax-handlers.php:29
authwp_ajax_wzconnector_test_connectionincludes\class-ajax-handlers.php:30
authwp_ajax_wzconnector_send_test_leadincludes\class-ajax-handlers.php:31
authwp_ajax_wzconnector_send_test_bookingincludes\class-ajax-handlers.php:32
authwp_ajax_wzconnector_submit_floating_formincludes\class-ajax-handlers.php:33
noprivwp_ajax_wzconnector_submit_floating_formincludes\class-ajax-handlers.php:34
authwp_ajax_wzconnector_submit_bookingincludes\class-ajax-handlers.php:35
noprivwp_ajax_wzconnector_submit_bookingincludes\class-ajax-handlers.php:36
authwp_ajax_wzconnector_retry_log_entryincludes\class-ajax-handlers.php:37
authwp_ajax_wzconnector_debug_booking_configincludes\class-ajax-handlers.php:38
authwp_ajax_wzconnector_sync_booking_dataincludes\class-ajax-handlers.php:39
authwp_ajax_wzconnector_save_tab_settingsincludes\class-ajax-handlers.php:40
authwp_ajax_wzconnector_dev_reinitincludes\class-ajax-handlers.php:45

Shortcodes 5

[workzen_reviews] includes\class-reviews.php:21
[workzen-lead-form] includes\class-shortcodes.php:21
[workzen-scheduler] includes\class-shortcodes.php:22
[workzen-lead-form-button] includes\class-shortcodes.php:23
[workzen-scheduler-button] includes\class-shortcodes.php:24
WordPress Hooks 28
actionwp_footerincludes\class-floating-buttons.php:103
actionwp_footerincludes\class-shortcodes.php:249
actionwp_footerincludes\class-shortcodes.php:284
actioninitincludes\class-workzen-connector.php:75
actionadmin_initincludes\class-workzen-connector.php:78
actionadmin_menuincludes\class-workzen-connector.php:81
actionadmin_enqueue_scriptsincludes\class-workzen-connector.php:82
actionadmin_noticesincludes\class-workzen-connector.php:83
actionplugins_loadedincludes\class-workzen-connector.php:86
actionwzconnector_process_queueincludes\class-workzen-connector.php:89
actionwp_enqueue_scriptsincludes\class-workzen-connector.php:95
actionwp_enqueue_scriptsincludes\class-workzen-connector.php:96
actionwp_footerincludes\class-workzen-connector.php:97
actionwzc_daily_heartbeatincludes\class-workzen-connector.php:106
actionupdate_optionincludes\class-workzen-connector.php:109
actionadmin_initincludes\class-workzen-connector.php:110
actionwpcf7_mail_sentintegrations\contact-form-7.php:10
filteret_pb_contact_form_submitintegrations\divi.php:9
actionelementor_pro/forms/new_recordintegrations\elementor.php:10
actioneverest_forms_process_completeintegrations\everest-forms.php:9
actionfluentform_submission_insertedintegrations\fluent-forms.php:9
actionfrm_after_create_entryintegrations\formidable-forms.php:9
actionforminator_custom_form_submit_before_set_fieldsintegrations\forminator.php:9
actiongform_after_submissionintegrations\gravity-forms.php:10
actionhouzez_after_submissionintegrations\houzez.php:9
actionmetform_after_form_submitintegrations\metform.php:9
actionninja_forms_after_submissionintegrations\ninja-forms.php:10
actionwpforms_process_completeintegrations\wpforms.php:9

Scheduled Events 3

wzconnector_process_queue
wzconnector_process_queue
wzc_daily_heartbeat
Maintenance & Trust

WorkZen Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads469

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WorkZen Connector Developer Profile

Ika Balzam

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WorkZen Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/workzen-connector/assets/js/wzc-admin-scripts.js/wp-content/plugins/workzen-connector/assets/css/wzc-admin-styles.css/wp-content/plugins/workzen-connector/assets/js/wzc-frontend-scripts.js/wp-content/plugins/workzen-connector/assets/css/wzc-frontend-styles.css/wp-content/plugins/workzen-connector/assets/images/workzen-sloth-icon.svg
Script Paths
/wp-content/plugins/workzen-connector/assets/js/wzc-admin-scripts.js/wp-content/plugins/workzen-connector/assets/js/wzc-frontend-scripts.js
Version Parameters
workzen-connector/assets/js/wzc-admin-scripts.js?ver=workzen-connector/assets/css/wzc-admin-styles.css?ver=workzen-connector/assets/js/wzc-frontend-scripts.js?ver=workzen-connector/assets/css/wzc-frontend-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
wzc-admin-settings-pagewzc-queue-tablewzc-integration-list-itemwzc-lead-form-wrapperwzc-floating-button
HTML Comments
<!-- WorkZen Connector Settings Page --><!-- WorkZen Connector Queue Table --><!-- End WorkZen Connector Queue Table --><!-- Floating WorkZen Button -->+1 more
Data Attributes
data-workzen-endpointdata-workzen-integration-keydata-wzc-form-id
JS Globals
window.WZC_Adminwindow.WZC_Frontendvar wzc_ajax_object
REST Endpoints
/wp-json/workzen-connector/v1/settings/wp-json/workzen-connector/v1/send-lead
Shortcode Output
<div class="workzen-connector-shortcode"><a href="#" class="wzc-book-appointment-button">Book Appointment</a></div>
FAQ

Frequently Asked Questions about WorkZen Connector