Agile CRM Gravity Forms Security & Risk Analysis

wordpress.org/plugins/agile-crm-gravity-forms

Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation

100 active installs v2.0 PHP + WP 3.0.1+ Updated Jan 30, 2019
agile-crmcrmcrm-plugincustomer-relationship-managementsmall-business-crm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Agile CRM Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Agile CRM Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "agile-crm-gravity-forms" v2.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerabilities (CVEs). The taint analysis also reveals no critical or high-severity unsanitized flows, suggesting a generally careful approach to handling user input in sensitive operations.

However, significant concerns arise from the static analysis. The plugin exposes two AJAX entry points, with one lacking authentication checks. This unprotected AJAX handler presents a clear attack vector. Furthermore, the output escaping is alarmingly low, with only 9% of 11 outputs properly escaped. This deficiency drastically increases the risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site through unescaped data displayed to users.

Despite the absence of past vulnerabilities and secure SQL practices, the identified weaknesses in authentication for an AJAX handler and pervasive output escaping issues create a substantial risk. The plugin's strengths in SQL handling and lack of historical CVEs are overshadowed by its susceptibility to direct attacks via an unprotected endpoint and likely XSS vulnerabilities. Therefore, while the plugin has some good security foundations, these critical oversights necessitate immediate attention.

Key Concerns

  • AJAX handler without authentication checks
  • Poor output escaping (9% properly escaped)
Vulnerabilities
None known

Agile CRM Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Agile CRM Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
1 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
5
Bundled Libraries
0

Output Escaping

9% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
map_form_fields (agilecrm-gravityforms.php:234)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Agile CRM Gravity Forms Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_agilecrm_gf_load_fieldsagilecrm-gravityforms.php:39
authwp_ajax_agilecrm_gf_map_fieldsagilecrm-gravityforms.php:40
WordPress Hooks 5
actioninitagilecrm-gravityforms.php:31
actionwp_footeragilecrm-gravityforms.php:32
actionadmin_initagilecrm-gravityforms.php:34
actionadmin_menuagilecrm-gravityforms.php:35
actiongform_after_submissionagilecrm-gravityforms.php:37
Maintenance & Trust

Agile CRM Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedJan 30, 2019
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Agile CRM Gravity Forms Developer Profile

Agile CRM

9 plugins · 860 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Agile CRM Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/agile-crm-gravity-forms/css/style.css/wp-content/plugins/agile-crm-gravity-forms/js/agilecrm_gf_admin.js
Script Paths
/wp-content/plugins/agile-crm-gravity-forms/js/agilecrm_gf_admin.js
Version Parameters
agile-crm-gravity-forms/css/style.css?ver=agile-crm-gravity-forms/js/agilecrm_gf_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
nav-tab-wrappernav-tab-activenav-tab
JS Globals
agilecrm_gf_load_fields_ajaxurlagilecrm_gf_map_fields_ajaxurl
REST Endpoints
/wp-json/agilecrm_gf
FAQ

Frequently Asked Questions about Agile CRM Gravity Forms