BCT for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/bct-for-gravity-forms

Description: Button Click Text is a really simple way for people using your form to see that your form is actually working when they push the submit b …

10 active installs v1.0.1 PHP + WP + Updated Jun 3, 2023
addonbutton-click-textgravity-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BCT for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

BCT for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of 'bct-for-gravity-forms' v1.0.1 reveals an exceptionally clean code surface with no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries is a strong indicator of good security practices. The use of prepared statements for all SQL queries is also a significant positive. However, the analysis shows a complete lack of output escaping, which is a critical concern. While taint analysis and vulnerability history show no immediate threats, the unescaped output presents a significant blind spot that could be exploited if any data is ever processed or displayed by the plugin.

The plugin's lack of direct attack vectors and adherence to safe database practices are commendable. The vulnerability history being entirely clear suggests a well-maintained or very simply implemented plugin. The primary and most significant risk stems from the 0% output escaping. This means any data, if it were to be processed or rendered, could be susceptible to cross-site scripting (XSS) vulnerabilities. Although there are no current known CVEs, the potential for XSS due to unescaped output remains a substantial risk that needs immediate attention. The plugin's overall security posture is currently good due to the absence of exploitable entry points and safe database practices, but the unescaped output is a critical weakness that overshadows these strengths and requires remediation.

Key Concerns

  • No output escaping detected
Vulnerabilities
None known

BCT for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BCT for Gravity Forms Release Timeline

v1.0
Code Analysis
Analyzed Apr 16, 2026

BCT for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

BCT for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actiongform_loadedgf-button-text-addon.php:17
actionwp_enqueue_scriptsgf-button-text-addon.php:37
actionadmin_enqueue_scriptsgf-button-text-addon.php:38
actionplugins_loadedgf-button-text-addon.php:44
filtergform_pre_rendergf-button-text-addon.php:50
actiongform_field_standard_settingsgf-button-text-addon.php:78
actiongform_editor_jsgf-button-text-addon.php:94
Maintenance & Trust

BCT for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 3, 2023
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BCT for Gravity Forms Developer Profile

Frog Eat Fly

4 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BCT for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bct-for-gravity-forms/js/button.js
Script Paths
/wp-content/plugins/bct-for-gravity-forms/js/button.js
Version Parameters
bct-for-gravity-forms/js/button.js?ver=bct_default_click_text

HTML / DOM Fingerprints

CSS Classes
submit_text_setting
Data Attributes
name="bct_default_click_text"id="switch_submit_text"
JS Globals
custom_button_data
FAQ

Frequently Asked Questions about BCT for Gravity Forms