
BCT for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/bct-for-gravity-formsDescription: Button Click Text is a really simple way for people using your form to see that your form is actually working when they push the submit b …
Is BCT for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 85/100BCT for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'bct-for-gravity-forms' v1.0.1 reveals an exceptionally clean code surface with no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries is a strong indicator of good security practices. The use of prepared statements for all SQL queries is also a significant positive. However, the analysis shows a complete lack of output escaping, which is a critical concern. While taint analysis and vulnerability history show no immediate threats, the unescaped output presents a significant blind spot that could be exploited if any data is ever processed or displayed by the plugin.
The plugin's lack of direct attack vectors and adherence to safe database practices are commendable. The vulnerability history being entirely clear suggests a well-maintained or very simply implemented plugin. The primary and most significant risk stems from the 0% output escaping. This means any data, if it were to be processed or rendered, could be susceptible to cross-site scripting (XSS) vulnerabilities. Although there are no current known CVEs, the potential for XSS due to unescaped output remains a substantial risk that needs immediate attention. The plugin's overall security posture is currently good due to the absence of exploitable entry points and safe database practices, but the unescaped output is a critical weakness that overshadows these strengths and requires remediation.
Key Concerns
- No output escaping detected
BCT for Gravity Forms Security Vulnerabilities
BCT for Gravity Forms Release Timeline
BCT for Gravity Forms Code Analysis
Output Escaping
BCT for Gravity Forms Attack Surface
WordPress Hooks 7
Maintenance & Trust
BCT for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
BCT for Gravity Forms Alternatives
Multi Page Auto Advance for Gravity Forms
auto-advance-for-gravity-forms
Description: The Auto Advance plugin for Gravity Forms makes the form filling process quicker and more user friendly for visitors.
Real Time Validation for Gravity Forms
real-time-validation-for-gravity-forms
Real Time Validation for Gravity Forms increases conversion rates of your Gravity Form using inline validation messages as user types in field.
Retrigger Notifications Gravity Forms
retrigger-notifications-gravity-forms
Resend Gravity Forms entry data to Zapier and Webhook feeds with one click -- no need to resubmit the form.
WP Gravity Forms HubSpot
gf-hubspot
Gravity Forms HubSpot Add-on sends Gravity Forms entries to HubSpot.
WP-Stateless – Gravity Forms Addon
wp-stateless-gravity-forms-addon
Provides compatibility between the Gravity Forms and the WP-Stateless plugins.
BCT for Gravity Forms Developer Profile
4 plugins · 2K total installs
How We Detect BCT for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bct-for-gravity-forms/js/button.js/wp-content/plugins/bct-for-gravity-forms/js/button.jsbct-for-gravity-forms/js/button.js?ver=bct_default_click_textHTML / DOM Fingerprints
submit_text_settingname="bct_default_click_text"id="switch_submit_text"custom_button_data