
Lead Form Data Collection to CRM Security & Risk Analysis
wordpress.org/plugins/wp-leads-builder-any-crmConvert contact forms data into leads or contacts directly to one of your favourite CRM.
Is Lead Form Data Collection to CRM Safe to Use in 2026?
Generally Safe
Score 96/100Lead Form Data Collection to CRM has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-leads-builder-any-crm' plugin version 3.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, with 96% using prepared statements, and a high rate of output escaping (85%). The plugin also shows a strong emphasis on security checks with 36 nonce checks and 35 capability checks, contributing to a relatively small attack surface with only one unprotected entry point. However, there are significant concerns related to the handling of serialized data and potential input sanitization issues.
The static analysis reveals the use of the `unserialize` function seven times, which is a known vector for deserialization vulnerabilities if not handled with extreme caution, especially with user-controlled input. Furthermore, the taint analysis identified 13 flows with unsanitized paths, including 11 of high severity. This suggests a substantial risk of attackers being able to inject malicious data into the application, potentially leading to code execution or data manipulation.
The vulnerability history indicates a past pattern of security weaknesses, with three known CVEs, including one high-severity vulnerability. The common vulnerability types, such as Missing Authorization and SQL Injection, alongside the high-severity taint flows, strongly suggest that proper input validation and authorization checks have been a recurring challenge for this plugin. While there are currently no unpatched CVEs, the history and analysis findings point to a need for continuous vigilance and robust development practices to mitigate future risks.
Key Concerns
- High severity taint flows detected
- Unsanitized paths in taint analysis
- Dangerous function 'unserialize' used
- Past high severity CVEs
- Past medium severity CVEs
- External HTTP requests present
Lead Form Data Collection to CRM Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions
Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
Lead Form Data Collection to CRM <= 3.0.1 - Authenticated (Contributor+) SQL Injection
Lead Form Data Collection to CRM Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Lead Form Data Collection to CRM Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
Lead Form Data Collection to CRM Maintenance & Trust
Maintenance Signals
Community Trust
Lead Form Data Collection to CRM Alternatives
CRM Connector Plus
crm-connector-plus
WordPress to CRM/Helpdesk Integration.
Zoho CRM Lead Magnet
zoho-crm-forms
Websites are one of the most important sources of leads for your business.
DoLeads Integrator
doleads-integrator
DoLeads Integrator plugin connects your wordpress website contact form with 'DoLeads' Leads Management System.
Happierleads – Identify your B2B website visitors even if they work remotely
happierleads
Identify your B2B website visitors that work remotely Generate 3X more leads than your competition by using your existing web traffic
Wise Agent Lead Forms
wiseagentleadform
Short Description: The Wise Agent WordPress plugin lets you easily add capture forms to any page on your WordPress site.
Lead Form Data Collection to CRM Developer Profile
20 plugins · 40K total installs
How We Detect Lead Form Data Collection to CRM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-leads-builder-any-crm/assets/css/bootstrap.css/wp-content/plugins/wp-leads-builder-any-crm/assets/css/bootstrap.min.css/wp-content/plugins/wp-leads-builder-any-crm/assets/css/font-awesome/css/font-awesome.css/wp-content/plugins/wp-leads-builder-any-crm/assets/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/wp-leads-builder-any-crm/assets/css/sweetalert.css/wp-content/plugins/wp-leads-builder-any-crm/assets/css/mainstyle.css/wp-content/plugins/wp-leads-builder-any-crm/assets/js/sweetalert-dev.js/wp-content/plugins/wp-leads-builder-any-crm/assets/js/notify.js+9 more/wp-content/plugins/wp-leads-builder-any-crm/assets/js/sweetalert-dev.js/wp-content/plugins/wp-leads-builder-any-crm/assets/js/notify.js/wp-content/plugins/wp-leads-builder-any-crm/assets/js/basicaction.js/wp-content/plugins/wp-leads-builder-any-crm/assets/js/Droptable.js/wp-content/plugins/wp-leads-builder-any-crm/assets/js/bootstrap.min.js/wp-content/plugins/wp-leads-builder-any-crm/assets/js/bootstrap-modal.min.js+2 morewp-leads-builder-any-crm/assets/css/bootstrap.css?ver=wp-leads-builder-any-crm/assets/css/bootstrap.min.css?ver=wp-leads-builder-any-crm/assets/css/font-awesome/css/font-awesome.css?ver=wp-leads-builder-any-crm/assets/css/font-awesome/css/font-awesome.min.css?ver=wp-leads-builder-any-crm/assets/css/sweetalert.css?ver=wp-leads-builder-any-crm/assets/css/mainstyle.css?ver=wp-leads-builder-any-crm/assets/js/sweetalert-dev.js?ver=wp-leads-builder-any-crm/assets/js/notify.js?ver=wp-leads-builder-any-crm/assets/js/basicaction.js?ver=wp-leads-builder-any-crm/assets/js/Droptable.js?ver=wp-leads-builder-any-crm/assets/js/bootstrap.min.js?ver=wp-leads-builder-any-crm/assets/js/bootstrap-modal.min.js?ver=wp-leads-builder-any-crm/assets/css/leads-builder.css?ver=wp-leads-builder-any-crm/assets/css/bootstrap-select.css?ver=wp-leads-builder-any-crm/assets/js/bootstrap-select.js?ver=wp-leads-builder-any-crm/assets/css/icheck/green.css?ver=wp-leads-builder-any-crm/assets/js/icheck.js?ver=HTML / DOM Fingerprints
sm-lb-form-fieldssm-lb-custom-btn<!-- WP Leads Builder For Any CRM --><!-- WP Leads Builder For Any CRM Pro -->data-toggle="modal"data-target="#lb-modal"sm_lb_params