Connect Brevo With Gravity Forms Security & Risk Analysis

wordpress.org/plugins/connect-brevo-gravity-forms

When someone submits a form on your site, it sends form submissions from Gravity Forms to the relationship marketing platform Brevo (ex Sendinblue).

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Oct 30, 2024
brevogravity-formsnewsletterpluginscafesubscribe
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connect Brevo With Gravity Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Connect Brevo With Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "connect-brevo-gravity-forms" v1.0.0 demonstrates a strong security posture based on the provided static analysis. There is a notable absence of common attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited. Furthermore, the code signals indicate good development practices with no dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The presence of file operations and external HTTP requests are inherent to many plugin functionalities and do not inherently indicate risk without further context, but the analysis shows no unsanitized paths or critical/high severity taint flows.

The vulnerability history is also entirely clean, with no known CVEs. This indicates a potentially well-maintained codebase or a lack of historical scrutiny. However, the complete lack of capability checks and nonce checks across all entry points is a significant concern. While the static analysis reports zero entry points needing these checks, the general absence of these fundamental WordPress security mechanisms is a weakness. In the event that future updates introduce new entry points or if the static analysis is incomplete, the plugin would be highly vulnerable to privilege escalation or cross-site request forgery attacks.

In conclusion, the plugin exhibits excellent adherence to secure coding practices regarding SQL, output escaping, and the absence of critical taint flows. The lack of a vulnerability history is a positive sign. However, the complete absence of capability and nonce checks across the board is a notable area of concern that significantly detracts from an otherwise strong security profile.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Connect Brevo With Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Connect Brevo With Gravity Forms Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Connect Brevo With Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Connect Brevo With Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtergform_entry_detail_meta_boxesclass-brevo-feed.php:50
actionadmin_noticesgf-brevo.php:26
actiongform_loadedgf-brevo.php:44
actioninitgf-brevo.php:53
Maintenance & Trust

Connect Brevo With Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 30, 2024
PHP min version7.4
Downloads918

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Connect Brevo With Gravity Forms Developer Profile

PluginsCafe

16 plugins · 12K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Connect Brevo With Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connect-brevo-gravity-forms/assets/images/brevo.svg

HTML / DOM Fingerprints

CSS Classes
brevo_created_profile_info
Data Attributes
data-field-map-source
JS Globals
pcafe_gfbr_brevo
FAQ

Frequently Asked Questions about Connect Brevo With Gravity Forms