
Cashfree Gravity Forms Security & Risk Analysis
wordpress.org/plugins/cashfree-gravity-formsAllows you to use Cashfree payment gateway with the gravity forms plugin.
Is Cashfree Gravity Forms Safe to Use in 2026?
Generally Safe
Score 85/100Cashfree Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cashfree-gravity-forms" plugin version 1.3.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs and the lack of critical findings in the taint analysis are strong indicators of a well-maintained and relatively secure codebase. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output, which mitigates common web vulnerabilities like SQL injection and cross-site scripting (XSS).
However, there are areas for concern that warrant attention. The presence of two flows with unsanitized paths in the taint analysis, although not classified as critical or high severity, suggests potential weaknesses in how file paths or user-controlled input is handled, which could be exploited in certain scenarios. Furthermore, the complete absence of nonce checks and capability checks is a significant oversight. This lack of authorization and validation on potential entry points (even if currently zero) means that if new entry points are introduced or if existing ones are overlooked in future development, they could be vulnerable to unauthorized access or actions.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in areas like SQL querying and output escaping, the identified unsanitized paths and the complete lack of nonces and capability checks represent notable security weaknesses. These areas, if not addressed, could introduce vulnerabilities in the future, especially as the plugin evolves. A proactive approach to implementing proper authorization and input sanitization for all potential entry points is recommended to bolster its security.
Key Concerns
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Low percentage of properly escaped output (15%)
Cashfree Gravity Forms Security Vulnerabilities
Cashfree Gravity Forms Code Analysis
Output Escaping
Data Flow Analysis
Cashfree Gravity Forms Attack Surface
WordPress Hooks 5
Maintenance & Trust
Cashfree Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Cashfree Gravity Forms Alternatives
Docket Connector
docket-connector
Create invoices within your Docket account from Gravity Forms.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
گرویتی فرم فارسی
persian-gravity-forms
بسته کامل فارسی ساز گرویتی فرم
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Cashfree Gravity Forms Developer Profile
2 plugins · 200 total installs
How We Detect Cashfree Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cashfree-gravity-forms/cashfree.php/wp-content/plugins/cashfree-gravity-forms/class-gf-cashfree.php/wp-content/plugins/cashfree-gravity-forms/assets/js/admin_script.js/wp-content/plugins/cashfree-gravity-forms/assets/css/admin_style.csscashfree-gravity-forms/assets/js/admin_script.jscashfree-gravity-forms/assets/js/admin_script.js?ver=cashfree-gravity-forms/assets/css/admin_style.css?ver=HTML / DOM Fingerprints
gform_cashfree_settings_sectiongform-cashfree-webhook-section<!--Cashfree Settings--><!--Cashfree Setup--><!--Cashfree Live/Sandbox Mode--><!--Cashfree Webhook Settings-->data-plugin-slug="cashfree-gravity-forms"cashfree_admin_params/wp-json/cashfree-gravity-forms/v1/webhook