
WP-CRM System – Manage Clients and Projects Security & Risk Analysis
wordpress.org/plugins/wp-crm-systemWP-CRM System – Manage Clients and Projects is a WordPress CRM that is designed to work exclusively with YOUR WordPress site.
Is WP-CRM System – Manage Clients and Projects Safe to Use in 2026?
Use With Caution
Score 67/100WP-CRM System – Manage Clients and Projects has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-crm-system plugin v3.4.6 exhibits a mixed security posture. On the positive side, the static analysis reveals a robust implementation of security best practices, with all identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) appearing to have proper authentication or permission checks. A high percentage of SQL queries utilize prepared statements, and output escaping is extensively implemented, suggesting a good level of developer awareness regarding common web vulnerabilities. Nonce and capability checks are also frequently used.
However, concerns arise from the taint analysis, which identified three high-severity flows with unsanitized paths. While no critical taint issues were found, these high-severity flows represent a significant risk, potentially leading to vulnerabilities if not addressed. The vulnerability history is also a notable concern. With a total of six known CVEs, including one currently unpatched high-severity vulnerability, and past common vulnerability types like Missing Authorization, Deserialization of Untrusted Data, and Cross-site Scripting, the plugin has a history of security weaknesses. The recent nature of the last reported vulnerability, despite being in the future (2026), is anomalous and warrants investigation but assuming it's a typo and reflects a recent discovery, it indicates ongoing issues.
In conclusion, while the plugin demonstrates strong adherence to fundamental security practices in its current codebase, the identified high-severity taint flows and its historical vulnerability record present substantial risks. The presence of an unpatched high-severity CVE is particularly alarming. Users should be cautious and prioritize patching and addressing the identified taint issues.
Key Concerns
- Unpatched high severity CVE
- High severity taint flows
- Bundled outdated library (Select2 v4.0.13)
- Vulnerability history with common types
WP-CRM System – Manage Clients and Projects Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
WP-CRM System – Manage Clients and Projects <= 3.4.5 - Missing Authorization to Authenticated (Subscriber+) CRM Data Exposure and Task Modification
WP-CRM System <= 3.4.5 - Missing Authorization
WP-CRM System <= 3.4.2 - Missing Authorization
WP-CRM System <= 3.4.5 - Authenticated (Administrator+) PHP Object Injection
WordPress CRM Plugin – WP-CRM System <= 3.2.9.1 - Missing Authorization
WP-CRM System <= 3.2.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP-CRM System – Manage Clients and Projects Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-CRM System – Manage Clients and Projects Attack Surface
AJAX Handlers 9
Shortcodes 2
WordPress Hooks 198
Scheduled Events 1
Maintenance & Trust
WP-CRM System – Manage Clients and Projects Maintenance & Trust
Maintenance Signals
Community Trust
WP-CRM System – Manage Clients and Projects Alternatives
Groundhogg — CRM, Newsletters, and Marketing Automation
groundhogg
Groundhogg is the best WordPress CRM & Marketing Automation plugin. Create flows, email campaigns, and have a CRM all within your WordPress site.
Meta Counter For Groundhogg | An Counter Action Extension
meta-counter-groundhogg
A Free Extension for Groundhogg: Adds an action that lets you count any funnel step and stores it in a chosen meta field.
QuarkLeads
quarkleads
Connect your WordPress contact forms directly to QuarkLeads CRM — and turn every website inquiry into an actionable lead instantly.
Flamingo
flamingo
A trustworthy message storage plugin for Contact Form 7.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
WP-CRM System – Manage Clients and Projects Developer Profile
13 plugins · 5K total installs
How We Detect WP-CRM System – Manage Clients and Projects
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-crm-system/assets/css/wp-crm-system-admin.css/wp-content/plugins/wp-crm-system/assets/css/wp-crm-system-customizer.css/wp-content/plugins/wp-crm-system/assets/css/wp-crm-system-frontend.css/wp-content/plugins/wp-crm-system/assets/css/wp-crm-system-frontend-editor.css/wp-content/plugins/wp-crm-system/assets/css/wp-crm-system-vendors.css/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-admin.js/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-frontend.js/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-vendors.js+2 more/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-admin.js/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-frontend.js/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-vendors.js/wp-content/plugins/wp-crm-system/assets/js/wp-crm-system-frontend-editor.js/wp-content/plugins/wp-crm-system/assets/js/wcs-recurring.jswp-crm-system/assets/css/wp-crm-system-admin.css?ver=wp-crm-system/assets/css/wp-crm-system-customizer.css?ver=wp-crm-system/assets/css/wp-crm-system-frontend.css?ver=wp-crm-system/assets/css/wp-crm-system-frontend-editor.css?ver=wp-crm-system/assets/css/wp-crm-system-vendors.css?ver=wp-crm-system/assets/js/wp-crm-system-admin.js?ver=wp-crm-system/assets/js/wp-crm-system-frontend.js?ver=wp-crm-system/assets/js/wp-crm-system-vendors.js?ver=wp-crm-system/assets/js/wp-crm-system-frontend-editor.js?ver=wp-crm-system/assets/js/wcs-recurring.js?ver=HTML / DOM Fingerprints
wp-crm-system-wrapwp-crm-system-admin-menuwcs-admin-pagewcs-section-titlewcs-form-fieldwcs-buttonwcs-client-listwcs-contact-details+8 moreIncludes for WP-CRM SystemRun Updates if NeededInclude system variablesWelcome screen+26 moredata-wpcrm-iddata-wpcrm-actiondata-wcs-field-typedata-wcs-modal-targetwpCrmSystemAdminwpCrmSystemFrontendwcsRecurring/wp-json/wp-crm-system/v1/contacts/wp-json/wp-crm-system/v1/projects/wp-json/wp-crm-system/v1/tasks/wp-json/wp-crm-system/v1/opportunities/wp-json/wp-crm-system/v1/campaigns/wp-json/wp-crm-system/v1/organizations[wps_crm_contact_form][wps_crm_client_list][wps_crm_project_list][wps_crm_task_list]