Addon Submission Blocker for Gravityforms Security & Risk Analysis

wordpress.org/plugins/addon-submission-blocker-for-gravityforms

Block specific emails, domains, IPs, countries, and text in Gravity Forms submissions with logging and statistics.

40 active installs v1.7.0 PHP 7.4+ WP 5.2+ Updated Feb 19, 2026
email-blockergravity-formsip-blockerspam-preventiontext-blocker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Addon Submission Blocker for Gravityforms Safe to Use in 2026?

Generally Safe

Score 100/100

Addon Submission Blocker for Gravityforms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "addon-submission-blocker-for-gravityforms" plugin v1.7.0 exhibits a generally good security posture, with no known past vulnerabilities and a strong emphasis on security checks within its code. The plugin successfully employs nonce checks and capability checks for its entry points. Furthermore, a high percentage of SQL queries are prepared, and a majority of outputs are properly escaped, indicating developers have followed common security best practices. However, there are areas for improvement. The presence of two unsanitized paths identified in the taint analysis is a concern, as these could potentially lead to security vulnerabilities if not handled with extreme care, despite the lack of critical or high severity flows in the current analysis. The plugin also performs file operations and makes external HTTP requests, which are always potential vectors for attack if not implemented securely. The absence of any recorded vulnerabilities to date is a positive indicator, suggesting the plugin has been developed with security in mind. However, the taint analysis highlights a potential weakness that warrants attention, even in the absence of confirmed exploits. Overall, the plugin is well-hardened, but the identified unsanitized paths represent a specific area of risk that should be prioritized for review.

Key Concerns

  • Flows with unsanitized paths found
  • File operations performed
  • External HTTP requests made
Vulnerabilities
None known

Addon Submission Blocker for Gravityforms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Addon Submission Blocker for Gravityforms Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
10 prepared
Unescaped Output
20
101 escaped
Nonce Checks
6
Capability Checks
4
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

59% prepared17 total queries

Output Escaping

83% escaped121 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
render_block_entry_page (includes\admin-settings.php:316)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Addon Submission Blocker for Gravityforms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_asbfg_quick_blockincludes\validation.php:16
WordPress Hooks 15
filtergform_settings_menuincludes\admin-settings.php:10
actiongform_settings_asbfg_submission_blockerincludes\admin-settings.php:11
actionadmin_initincludes\admin-settings.php:12
actionadmin_menuincludes\admin-settings.php:13
actionadmin_enqueue_scriptsincludes\admin-settings.php:14
actionadmin_post_asbfg_export_settingsincludes\admin-settings.php:15
actionadmin_post_asbfg_import_settingsincludes\admin-settings.php:16
actionadmin_menuincludes\logger.php:23
actionadmin_post_asbfg_clear_logsincludes\logger.php:24
actionadmin_enqueue_scriptsincludes\logger.php:25
actionasbfg_cleanup_old_logsincludes\logger.php:31
filtergform_field_validationincludes\validation.php:12
filtergform_entries_first_column_actionsincludes\validation.php:13
actiongform_entry_detail_sidebar_beforeincludes\validation.php:14
actionadmin_enqueue_scriptsincludes\validation.php:15

Scheduled Events 1

asbfg_cleanup_old_logs
Maintenance & Trust

Addon Submission Blocker for Gravityforms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Addon Submission Blocker for Gravityforms Developer Profile

Ishor Ale Magar

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Addon Submission Blocker for Gravityforms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addon-submission-blocker-for-gravityforms/assets/admin-styles.css
Version Parameters
addon-submission-blocker-for-gravityforms/assets/admin-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
asbfg-toolbargform-settings__content
Data Attributes
data-formfield="asbfg_blocked_ips"data-formfield="asbfg_blocked_emails"data-formfield="asbfg_blocked_domains"data-formfield="asbfg_blocked_countries"data-formfield="asbfg_custom_ip_message"data-formfield="asbfg_custom_email_message"+5 more
FAQ

Frequently Asked Questions about Addon Submission Blocker for Gravityforms