
Add-on for Gravity Forms + Bento Security & Risk Analysis
wordpress.org/plugins/add-on-gravity-forms-bentoThis community plugin allows you to connect your forms created in Gravity Forms to the Bento marketing automation platform.
Is Add-on for Gravity Forms + Bento Safe to Use in 2026?
Generally Safe
Score 85/100Add-on for Gravity Forms + Bento has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of add-on-gravity-forms-bento v2.0 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices by having zero identified dangerous functions, all SQL queries utilizing prepared statements, and 100% of outputs being properly escaped. Furthermore, the absence of any file operations, known CVEs, or recorded vulnerabilities in its history suggests a well-maintained and secure codebase.
However, there are a couple of areas that warrant attention. The plugin makes one external HTTP request, and without further context, it's impossible to definitively assess its security implications. If this request is not properly validated or if the target is untrusted, it could introduce risks. Additionally, the complete absence of nonces and capability checks across all identified entry points (though limited) is a significant concern. This means that even if entry points existed, they might not be adequately protected against unauthorized access or actions, representing a potential weakness that could be exploited if any unintended entry points are discovered or if future updates introduce them without proper security measures.
In conclusion, while the plugin's current codebase appears robust and free of known vulnerabilities, the single external HTTP request and the complete lack of nonce and capability checks indicate areas where security could be further strengthened to ensure a more comprehensive defense against potential threats.
Key Concerns
- External HTTP request without apparent validation
- No nonce checks implemented
- No capability checks implemented
Add-on for Gravity Forms + Bento Security Vulnerabilities
Add-on for Gravity Forms + Bento Code Analysis
Add-on for Gravity Forms + Bento Attack Surface
WordPress Hooks 1
Maintenance & Trust
Add-on for Gravity Forms + Bento Maintenance & Trust
Maintenance Signals
Community Trust
Add-on for Gravity Forms + Bento Alternatives
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
Omnisend for Gravity Forms Add-On
omnisend-for-gravity-forms-add-on
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Klaviyo for Gravity Forms
klaviyo-for-gravity-forms
Klaviyo's list API integration for Gravity forms
Add-On for Gravity Forms + Rejoiner
gf-rejoiner
This plugin allows you to connect your forms created in Gravity Forms to the Rejoiner email platform.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Add-on for Gravity Forms + Bento Developer Profile
5 plugins · 150 total installs
How We Detect Add-on for Gravity Forms + Bento
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-on-gravity-forms-bento/assets/css/gf-bento-addon-settings.css/wp-content/plugins/add-on-gravity-forms-bento/assets/js/gf-bento-addon-settings.jsHTML / DOM Fingerprints
gf_bento_addon_settings_containerdata-plugin-name="add-on-gravity-forms-bento"data-plugin-version="2.0"gf_bento_addon_strings