CHIP for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/chip-for-gravity-forms

CHIP - Digital Finance Platform. Securely accept one-time payments with CHIP for Gravity Forms.

20 active installs v1.2.0 PHP 7.4+ WP 6.3+ Updated Feb 20, 2026
chipfpxgravity-formspaymentpayment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CHIP for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

CHIP for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "chip-for-gravity-forms" v1.2.0 demonstrates a generally good security posture based on the provided static analysis. The plugin has no identified vulnerabilities in its history, and the static analysis reveals no critical or high severity issues in taint flows. All SQL queries utilize prepared statements, which is a significant strength in preventing SQL injection. Output escaping is also predominantly handled correctly with 89% of outputs properly escaped, minimizing risks of cross-site scripting (XSS). The limited attack surface, with only two AJAX handlers and no shortcodes or cron events, further contributes to its security. Furthermore, the plugin includes nonce checks on its AJAX handlers, which is crucial for preventing CSRF attacks.

Key Concerns

  • Missing capability checks on AJAX handlers
  • One file operation detected
  • One external HTTP request detected
  • 11% of outputs are not properly escaped
Vulnerabilities
None known

CHIP for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CHIP for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
3
24 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

89% escaped27 total outputs
Attack Surface

CHIP for Gravity Forms Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_gf_chip_refund_paymentclass-gf-chip.php:119
authwp_ajax_gf_chip_get_global_credentialsclass-gf-chip.php:120
WordPress Hooks 4
actiongform_loadedchip-for-gravity-forms.php:27
actionwpclass-gf-chip.php:118
actiongform_post_payment_callbackclass-gf-chip.php:130
actiongform_post_save_feed_settingsclass-gf-chip.php:131
Maintenance & Trust

CHIP for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

CHIP for Gravity Forms Developer Profile

Chip In Sdn Bhd

5 plugins · 4K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CHIP for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chip-for-gravity-forms/assets/form-settings.png/wp-content/plugins/chip-for-gravity-forms/assets/logo.svg
Script Paths
/wp-content/plugins/chip-for-gravity-forms/assets/js/feed-settings-copy-global.js
Version Parameters
chip-for-gravity-forms/assets/js/feed-settings-copy-global.js?ver=v1.2.0

HTML / DOM Fingerprints

Data Attributes
data-gform-id
JS Globals
gform_chip_feed_settings_copy_global_params
REST Endpoints
/wp-json/gravityformschip/v1
FAQ

Frequently Asked Questions about CHIP for Gravity Forms