Multi Page Auto Advance for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/auto-advance-for-gravity-forms

Description: The Auto Advance plugin for Gravity Forms makes the form filling process quicker and more user friendly for visitors.

3K active installs v5.0.5 PHP + WP + Updated Feb 16, 2025
addonauto-advancegravity-formsmulti-formmulti-step
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Multi Page Auto Advance for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Multi Page Auto Advance for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'auto-advance-for-gravity-forms' plugin v5.0.5 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities or known CVEs. This suggests a development team that is mindful of common database exploitation vectors. However, a significant concern arises from its attack surface, with one AJAX handler lacking any authentication checks. This represents a direct entry point that could be exploited by unauthenticated users.

Further analysis reveals a critical weakness in output escaping, with only 2% of outputs properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. The absence of nonce checks on the unprotected AJAX handler exacerbates this risk, making it easier for attackers to inject malicious scripts. While the plugin has a clean vulnerability history, the presence of unprotected entry points and poor output sanitization indicates potential areas for exploitation that could be leveraged by attackers, despite the lack of historical incidents.

Key Concerns

  • AJAX handler without authentication
  • Low percentage of properly escaped outputs
  • Missing nonce checks
Vulnerabilities
None known

Multi Page Auto Advance for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multi Page Auto Advance for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
1 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

2% escaped51 total outputs
Attack Surface
1 unprotected

Multi Page Auto Advance for Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_aafg-notice-dismissauto-advance-for-gravity-forms.php:181
WordPress Hooks 12
filterpricing_urlauto-advance-for-gravity-forms.php:46
actiongform_loadedauto-advance-for-gravity-forms.php:53
actionplugins_loadedauto-advance-for-gravity-forms.php:65
actionadmin_noticesauto-advance-for-gravity-forms.php:180
filtergform_tooltipsphp\class-gfautoadvancedaddon.php:41
filtergform_pre_renderphp\class-gfautoadvancedaddon.php:47
filteradmin_enqueue_scriptsphp\class-gfautoadvancedaddon.php:48
filterwp_enqueue_scriptsphp\class-gfautoadvancedaddon.php:49
filtergform_form_post_get_metaphp\class-gfautoadvancedaddon.php:51
filtergform_form_settings_menuphp\class-gfautoadvancedaddon.php:57
filtergform_field_settings_tabsphp\class-gfautoadvancedaddon.php:64
filtergform_field_settings_tab_contentphp\class-gfautoadvancedaddon.php:70
Maintenance & Trust

Multi Page Auto Advance for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 16, 2025
PHP min version
Downloads60K

Community Trust

Rating90/100
Number of ratings19
Active installs3K
Developer Profile

Multi Page Auto Advance for Gravity Forms Developer Profile

Frog Eat Fly

3 plugins · 3K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multi Page Auto Advance for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-advance-for-gravity-forms/freemius/assets/css/notice.css/wp-content/plugins/auto-advance-for-gravity-forms/freemius/assets/js/notice.js/wp-content/plugins/auto-advance-for-gravity-forms/images/IMPORTANT UPDATE NOTICE.png/wp-content/plugins/auto-advance-for-gravity-forms/images/icon.png
Version Parameters
auto-advance-for-gravity-forms/auto-advance-for-gravity-forms.php?ver=auto-advance-for-gravity-forms/freemius/start.php?ver=

HTML / DOM Fingerprints

CSS Classes
aafg-notice-erroraafg-noticenotice-containerbig-imagenotice-imagebig-logonotice-contentnotice-heading+6 more
Data Attributes
id="aafg-notice-error"id="aafg-version-notice"id="aafg-notice"src="/wp-content/plugins/auto-advance-for-gravity-forms/images/IMPORTANT UPDATE NOTICE.png"src="/wp-content/plugins/auto-advance-for-gravity-forms/images/icon.png"
JS Globals
aafgf_fs
FAQ

Frequently Asked Questions about Multi Page Auto Advance for Gravity Forms