AcyMailing integration for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/acymailing-integration-for-gravity-forms

Add AcyMailing lists to your Gravity Forms forms

60 active installs v4.5 PHP + WP + Updated Feb 26, 2026
formgravity-formsnewsletternewsletter-formsubscription
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AcyMailing integration for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

AcyMailing integration for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of AcyMailing Integration for Gravity Forms v4.5 reveals a seemingly strong security posture based on the provided metrics. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication checks, indicating a proactive approach to limiting unauthorized access. Furthermore, the code demonstrates excellent practices in secure coding, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests also reduces potential attack vectors. The vulnerability history also shows a clean record with no known CVEs, suggesting a history of secure development or prompt patching.

However, a significant concern arises from the complete absence of nonce checks and capability checks, coupled with zero AJAX handlers and REST API routes. While this means there are no *unprotected* entry points in the analyzed data, it also implies that the plugin might not be utilizing WordPress's built-in security mechanisms for the few entry points it might have (if any were missed in the analysis). The lack of taint analysis results (zero flows analyzed) is also peculiar; it could mean the analysis tool was unable to find any flows or that the plugin simply doesn't have complex data flow interactions that would trigger such analysis. This, combined with the lack of capability checks, raises a potential risk that any internal functions could be manipulated if an attacker finds a way to call them, even if they aren't directly exposed as typical entry points.

In conclusion, while the plugin exhibits strong adherence to secure coding practices and has no documented vulnerabilities, the absence of nonce and capability checks, coupled with the zero taint flows, presents a potential blind spot. The plugin's strengths lie in its clean code and lack of known exploits, but the reliance on implicit security through lack of exposed entry points without explicit checks could be a weakness if unforeseen interaction methods are discovered or if the scope of static analysis was limited. A more thorough review considering how internal functions might be invoked without explicit entry points and the absence of capability checks would be beneficial.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • No taint flows analyzed
Vulnerabilities
None known

AcyMailing integration for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AcyMailing integration for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

AcyMailing integration for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionacym_load_installed_integrationsacymailing-gravityforms.php:26
actiongform_field_standard_settingsplugin.php:31
actiongform_editor_jsplugin.php:32
actiongform_after_submissionplugin.php:33
Maintenance & Trust

AcyMailing integration for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

AcyMailing integration for Gravity Forms Developer Profile

AcyMailing Newsletter Team

20 plugins · 8K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
298 days
View full developer profile
Detection Fingerprints

How We Detect AcyMailing integration for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AcyMailing integration for Gravity Forms