Beyond Pay for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/beyond-pay-for-gravity-forms

Securely accept credit card payments within Gravity Forms using Beyond Pay gateway and optimize your cost of acceptance on B2B/corporate cards.

0 active installs v1.2.2 PHP 7.0+ WP 4.7+ Updated Nov 7, 2024
credit-carddonationgravity-formspaymentpayment-gateway
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Beyond Pay for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Beyond Pay for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'beyond-pay-for-gravity-forms' plugin version 1.2.2 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped outputs. The absence of known vulnerabilities in its history, including critical or high-severity ones, is also a strong indicator of a generally secure development process. The plugin also avoids bundling external libraries, which can sometimes be a source of vulnerabilities.

However, the static analysis reveals a significant concern: a single AJAX handler that lacks authentication checks. This creates an unprotected entry point, which is a primary risk factor. While no dangerous functions or taint flows were identified, and SQL queries are secure, the presence of an unauthenticated AJAX endpoint can potentially be exploited for various malicious purposes depending on its functionality. The lack of nonce checks and capability checks on this handler further exacerbates the risk.

In conclusion, while the plugin benefits from a clean vulnerability history and secure database interactions, the unprotected AJAX endpoint is a critical weakness that needs immediate attention. This single flaw significantly outweighs the otherwise positive security attributes. Addressing this unauthenticated entry point should be the top priority to improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
  • Missing nonce checks
  • Missing capability checks
  • Unescaped output present
Vulnerabilities
None known

Beyond Pay for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Beyond Pay for Gravity Forms Release Timeline

v1.2.2Current
v1.2.1
v1.1.3
v1.1.2
v1.1.1
Code Analysis
Analyzed Apr 16, 2026

Beyond Pay for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

79% escaped14 total outputs
Attack Surface
1 unprotected

Beyond Pay for Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_beyond_pay_capturebeyond-pay-gravity-forms.php:50
WordPress Hooks 5
actiongform_loadedbeyond-pay-gravity-forms.php:19
actiongform_payment_detailsbeyond-pay-gravity-forms.php:37
actiongform_post_payment_actionincludes/gf-beyond-pay.php:36
filtergform_validation_messageincludes/gf-beyond-pay.php:37
filtergform_enable_credit_card_fieldincludes/gf-beyond-pay.php:42
Maintenance & Trust

Beyond Pay for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 7, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Beyond Pay for Gravity Forms Developer Profile

Beyond Pay

2 plugins · 40 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Beyond Pay for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/beyond-pay-gravity-forms/assets/css/payment-styling.css

HTML / DOM Fingerprints

CSS Classes
gf_payment_detailbeyond_pay_setting_test_onlybeyond_pay_setting_live_onlybeyond_pay_styling
Data Attributes
onclick="beyondPayCapturePayment(onBeyondPayTestModeChanged(this)onBeyondPayStylingChanged(this)
JS Globals
beyondPayCapturePayment
REST Endpoints
wp-json/beyond-pay-gravity-forms
Shortcode Output
<div id="gf_beyond_pay_invnum" class="gf_payment_detail"><span id='gform_beyond_pay_invnum'>
FAQ

Frequently Asked Questions about Beyond Pay for Gravity Forms