Add-on for Gravity Forms + Bento Security & Risk Analysis

wordpress.org/plugins/add-on-gravity-forms-bento

This community plugin allows you to connect your forms created in Gravity Forms to the Bento marketing automation platform.

30 active installs v2.0 PHP 7.2+ WP 4.6+ Updated Jul 27, 2022
bentoemail-marketinggravity-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Add-on for Gravity Forms + Bento Safe to Use in 2026?

Generally Safe

Score 85/100

Add-on for Gravity Forms + Bento has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of add-on-gravity-forms-bento v2.0 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices by having zero identified dangerous functions, all SQL queries utilizing prepared statements, and 100% of outputs being properly escaped. Furthermore, the absence of any file operations, known CVEs, or recorded vulnerabilities in its history suggests a well-maintained and secure codebase.

However, there are a couple of areas that warrant attention. The plugin makes one external HTTP request, and without further context, it's impossible to definitively assess its security implications. If this request is not properly validated or if the target is untrusted, it could introduce risks. Additionally, the complete absence of nonces and capability checks across all identified entry points (though limited) is a significant concern. This means that even if entry points existed, they might not be adequately protected against unauthorized access or actions, representing a potential weakness that could be exploited if any unintended entry points are discovered or if future updates introduce them without proper security measures.

In conclusion, while the plugin's current codebase appears robust and free of known vulnerabilities, the single external HTTP request and the complete lack of nonce and capability checks indicate areas where security could be further strengthened to ensure a more comprehensive defense against potential threats.

Key Concerns

  • External HTTP request without apparent validation
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Add-on for Gravity Forms + Bento Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add-on for Gravity Forms + Bento Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Add-on for Gravity Forms + Bento Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actiongform_loadedgf-bento-addon.php:13
Maintenance & Trust

Add-on for Gravity Forms + Bento Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 27, 2022
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Add-on for Gravity Forms + Bento Developer Profile

Jackson Whelan

5 plugins · 150 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add-on for Gravity Forms + Bento

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-on-gravity-forms-bento/assets/css/gf-bento-addon-settings.css/wp-content/plugins/add-on-gravity-forms-bento/assets/js/gf-bento-addon-settings.js

HTML / DOM Fingerprints

CSS Classes
gf_bento_addon_settings_container
Data Attributes
data-plugin-name="add-on-gravity-forms-bento"data-plugin-version="2.0"
JS Globals
gf_bento_addon_strings
FAQ

Frequently Asked Questions about Add-on for Gravity Forms + Bento