shouldiuse.io

VERDICT

Should I use Groundhogg™?

Groundhogg will help you launch your funnel, grow your list and scale your business faster with proven digital marketing tools and strategies! - groundhogg.io

Depends. Buy if your business already runs on WordPress and you will stay current on plugin security patches. Avoid it if you want hands-off hosted SaaS or cannot accept self-hosted breach liability.

Confidence

Medium. Based on ~13 public sources; no independent review aggregates (G2, Capterra) found in evidence.

Ratings

  • Value for money
  • Ease of useNo independent usability evidence in sources
  • Feature depth
  • Support quality
  • Security posture

Pricing

Flat-rate premium plans

Not disclosed in reviewed sources

ModelFlat-rate
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • WordPress-native small businesses
  • Agencies managing client funnels
  • Teams wanting flat-rate, feature-based pricing
  • Nonprofits using the vendor's grant program

Not for

  • Non-WordPress sites — it is a plugin, full stop
  • Anyone unwilling to patch plugin CVEs promptly
  • Security-sensitive orgs that need a vendor to hold breach liability
  • Buyers who require independent reviews before committing

Gotchas - check before you buy

high

Self-hosting shifts breach and data-leak liability entirely onto you

high

Web forms before 4.5.13 allowed unauthenticated stored XSS — update immediately

high

June 2025 supply-chain breach means auditing your install and rotating credentials

medium

15% discount applies only to the first subscription year; renewals at full price

Pros and cons

Pros

  • Flat-rate pricing based on features, not contact count or growth
  • Full CRM, newsletters, and marketing automation inside WordPress
  • Complimentary installation offered by the customer success team
  • Grant program helps nonprofits adopt CRM and automation
  • Certified partner network available for managed support

Cons

  • Repeated public CVEs: stored XSS, CSRF, path traversal, unauthorized data access
  • Disclosed targeted supply chain attack on June 27, 2025
  • Self-hosting makes breaches and data leaks your liability
  • Requires WordPress; not a standalone hosted product
  • Most visible reviews are self-published; independent review data is scarce

Sources & method

Analyzed 9/20/2026 - 13 sources - Multiple CVEs (stored XSS, CSRF, path traversal, unauthorized data access) plus a disclosed June 2025 supply-chain attack; patching discipline is mandatory.

official x4review x2security x6news x1
  • CVE-2026-81660 — unauthenticated stored XSS in web forms, Versions before 4.5.13 do not validate or escape some optional web form submissions.
  • CVE-2023-2716 — unauthorized data access, The plugin is vulnerable to unauthorized access of data.
  • CVE-2026-81741 — CSRF vulnerability, Cross-site request forgerness issue in the Groundhogg WordPress plugin.
  • CVE-2026-57389 — path traversal, Path traversal vulnerability in the Groundhogg plugin.
  • Supply chain attack, June 27, 2025, Vendor disclosed a targeted supply chain attack and is notifying affected customers.

Key stats

  • Value for money: 4/5

    Rating

  • Not disclosed

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 4/5. Flat-rate pricing decouples cost from list growth
  • Ease of use. No independent usability evidence in sources
  • Feature depth: 4/5. CRM, email, funnels, automation bundled in one plugin
  • Support quality: 4/5. Free installation, expert chat, certified partners, user group
  • Security posture: 1/5. Multiple CVEs plus disclosed supply chain breach
  • 2018 Founded Groundhogg Inc., WordPress-native CRM
  • Flat-rate Pricing model Feature-based, not usage- or growth-based
  • 5+ Named CVEs XSS, CSRF, path traversal, unauthorized data access
  • Jun 2025 Breach disclosure Targeted supply chain attack, customers notified

Pricing

Flat-rate premium plans

Not disclosed

  • Pricing based on features, not usage or growth
  • 15% off any premium plan for first subscription year

Security

Multiple CVEs (stored XSS, CSRF, path traversal, unauthorized data access) plus a disclosed June 2025 supply-chain attack; patching discipline is mandatory.

  • CVE-2026-81660 — unauthenticated stored XSS in web formsVersions before 4.5.13 do not validate or escape some optional web form submissions.⁴
  • CVE-2023-2716 — unauthorized data accessThe plugin is vulnerable to unauthorized access of data.⁵
  • CVE-2026-81741 — CSRF vulnerabilityCross-site request forgerness issue in the Groundhogg WordPress plugin.⁶
  • CVE-2026-57389 — path traversalPath traversal vulnerability in the Groundhogg plugin.⁷
  • Supply chain attack, June 27, 2025Vendor disclosed a targeted supply chain attack and is notifying affected customers.³

What users say

Self-published reviews and case studies are positive, but independent review volume is thin and security news dominates third-party coverage.

“How our son won over 1000 customers for his start up in under in ...”
LinkedIn article by Paul Tobey
“I've heard of customers getting their accounts terminated because of… Censorship”
Comment on Groundhogg About page

Companies that use it

  • Five Star Referral Network13
Full analysis

Based on ~13 public sources; no independent review aggregates (G2, Capterra) found in evidence.

Feature-rich WordPress CRM at flat rates — but 5+ CVEs and a 2025 supply-chain breach put security work on you.

Methodology

Based on ~13 public sources; no independent review aggregates (G2, Capterra) found in evidence.

Sources

  1. official
  2. official
  3. news
  4. security
  5. security
  6. security
  7. security
  8. security
  9. security
  10. official
  11. official
  12. review
  13. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.