WPOP's WPForms to HubSpot Security & Risk Analysis

wordpress.org/plugins/wpop-wpforms-to-hubspot

This plugin is a easy to use addon for WPforms which helps to send form data to HubSpot lists with very less configuration and easy to use interface.

60 active installs v1.0.5 PHP 5.6+ WP 4.7+ Updated Sep 16, 2022
addonshubspotwpformswpforms-and-hubspot
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPOP's WPForms to HubSpot Safe to Use in 2026?

Generally Safe

Score 85/100

WPOP's WPForms to HubSpot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "wpop-wpforms-to-hubspot" plugin v1.0.5 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of unprotected entry points (AJAX, REST API, shortcodes, cron events) is a significant positive, as is the lack of any detected dangerous functions, file operations, or SQL queries without prepared statements. The high percentage of properly escaped output further mitigates risks related to cross-site scripting (XSS).

However, there are a few areas that warrant attention. The plugin makes one external HTTP request, and while no specific risks are detailed, such requests can sometimes be vectors for vulnerabilities if not handled carefully, especially if they involve user-supplied data or insecure endpoints. More importantly, the complete lack of nonce checks and capability checks on any potential entry points is a critical concern. While the analysis indicates zero entry points were found, this could be an oversight in the analysis or the plugin might have features that are not immediately obvious as entry points. If any functionality were to be added or discovered later that does not implement these essential WordPress security mechanisms, it would expose the site to significant risks like cross-site request forgery (CSRF) and unauthorized access.

The vulnerability history being entirely clean is a strong indicator that the developers have historically prioritized security. This, combined with the good practices observed in the code analysis, suggests a commitment to security. Nevertheless, the absence of nonce and capability checks represents a potential blind spot that could be exploited if the attack surface were to expand. The plugin's strengths lie in its clean code regarding common web vulnerabilities, but its weakness lies in a potential gap in core WordPress security best practices.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • External HTTP Request (potential risk)
Vulnerabilities
None known

WPOP's WPForms to HubSpot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPOP's WPForms to HubSpot Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

WPOP's WPForms to HubSpot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
57 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

92% escaped62 total outputs
Attack Surface

WPOP's WPForms to HubSpot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterwpforms_settings_tabsincludes/hbwf-settings.php:37
filterwpforms_settings_defaultsincludes/hbwf-settings.php:39
filterwpforms_builder_settings_sectionsincludes/hbwf-settings.php:41
actionwpforms_form_settings_panel_contentincludes/hbwf-settings.php:43
actionwpforms_processincludes/hbwf-subscribe.php:10
actioninitwpop-wpforms-hubspot.php:24
actionwpforms_builder_enqueueswpop-wpforms-hubspot.php:26
actioninitwpop-wpforms-hubspot.php:27
actionadmin_noticeswpop-wpforms-hubspot.php:40
Maintenance & Trust

WPOP's WPForms to HubSpot Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 16, 2022
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

WPOP's WPForms to HubSpot Developer Profile

wpoperations

11 plugins · 17K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect WPOP's WPForms to HubSpot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpop-wpforms-hubspot/assets/admin.css

HTML / DOM Fingerprints

CSS Classes
wpforms-panel-content-section-hb-integration
Data Attributes
id="hb-apikey"id="hb-listid"id="hb-lifecycle-stage"id="hb-lead-status"name="hb-apikey"name="hb-listid"+6 more
Shortcode Output
<h4<p>Add your HubSpot API credentials here.This is a global setting area,you can also add Access Token seperately for each forms.HubSpot Access TokenYou can get Access Token like
FAQ

Frequently Asked Questions about WPOP's WPForms to HubSpot