Cashfree Gravity Forms Security & Risk Analysis

wordpress.org/plugins/cashfree-gravity-forms

Allows you to use Cashfree payment gateway with the gravity forms plugin.

100 active installs v1.3.0 PHP 7.0+ WP 3.9.2+ Updated Mar 1, 2024
cashfree-paymentse-commercegravityforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cashfree Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Cashfree Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "cashfree-gravity-forms" plugin version 1.3.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs and the lack of critical findings in the taint analysis are strong indicators of a well-maintained and relatively secure codebase. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output, which mitigates common web vulnerabilities like SQL injection and cross-site scripting (XSS).

However, there are areas for concern that warrant attention. The presence of two flows with unsanitized paths in the taint analysis, although not classified as critical or high severity, suggests potential weaknesses in how file paths or user-controlled input is handled, which could be exploited in certain scenarios. Furthermore, the complete absence of nonce checks and capability checks is a significant oversight. This lack of authorization and validation on potential entry points (even if currently zero) means that if new entry points are introduced or if existing ones are overlooked in future development, they could be vulnerable to unauthorized access or actions.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in areas like SQL querying and output escaping, the identified unsanitized paths and the complete lack of nonces and capability checks represent notable security weaknesses. These areas, if not addressed, could introduce vulnerabilities in the future, especially as the plugin evolves. A proactive approach to implementing proper authorization and input sanitization for all potential entry points is recommended to bolster its security.

Key Concerns

  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
  • Low percentage of properly escaped output (15%)
Vulnerabilities
None known

Cashfree Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cashfree Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

85% escaped39 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
callback (class-gf-cashfree.php:229)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cashfree Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_post_nopriv_gf_cashfree_notifycashfree.php:23
actiongform_loadedcashfree.php:24
filtergform_currenciescashfree.php:44
actiongform_after_submissionclass-gf-cashfree.php:150
filtergform_notification_eventsclass-gf-cashfree.php:664
Maintenance & Trust

Cashfree Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 1, 2024
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Cashfree Gravity Forms Developer Profile

Cashfree

2 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cashfree Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cashfree-gravity-forms/cashfree.php/wp-content/plugins/cashfree-gravity-forms/class-gf-cashfree.php/wp-content/plugins/cashfree-gravity-forms/assets/js/admin_script.js/wp-content/plugins/cashfree-gravity-forms/assets/css/admin_style.css
Script Paths
cashfree-gravity-forms/assets/js/admin_script.js
Version Parameters
cashfree-gravity-forms/assets/js/admin_script.js?ver=cashfree-gravity-forms/assets/css/admin_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
gform_cashfree_settings_sectiongform-cashfree-webhook-section
HTML Comments
<!--Cashfree Settings--><!--Cashfree Setup--><!--Cashfree Live/Sandbox Mode--><!--Cashfree Webhook Settings-->
Data Attributes
data-plugin-slug="cashfree-gravity-forms"
JS Globals
cashfree_admin_params
REST Endpoints
/wp-json/cashfree-gravity-forms/v1/webhook
FAQ

Frequently Asked Questions about Cashfree Gravity Forms