Connector GravityForms and MailerLite Security & Risk Analysis

wordpress.org/plugins/connector-gravityforms-mailerlite

This plugin connects GravityForms with MailerLite.

2K active installs v1.5 PHP + WP 4.0+ Updated Mar 24, 2023
genesiswidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connector GravityForms and MailerLite Safe to Use in 2026?

Generally Safe

Score 85/100

Connector GravityForms and MailerLite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "connector-gravityforms-mailerlite" plugin v1.5 presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis indicates good development practices with 100% of SQL queries using prepared statements and a high percentage of output escaping, minimizing common web vulnerabilities. The lack of recorded vulnerabilities, including CVEs, further supports a positive security assessment.

However, a few areas warrant attention. The presence of an external HTTP request without explicit mention of authentication or sanitization is a potential concern, as it could be a vector for information disclosure or manipulation if not handled securely. The absence of nonce checks and capability checks, while seemingly less critical given the zero attack surface, represents a missed opportunity for robust security, especially if the plugin's functionality were to expand or change in future versions. The fact that taint analysis showed zero flows might be due to the limited analysis scope or the plugin's design, but it doesn't entirely negate potential risks with external interactions.

In conclusion, this plugin appears to be developed with security in mind, demonstrating good practices in query handling and output sanitization, and it has a clean vulnerability history. The primary weaknesses lie in the potential risks associated with the external HTTP request and the lack of comprehensive security checks like nonces and capability checks, which are important for defense-in-depth. Overall, the risk is low, but these points should be considered for further hardening.

Key Concerns

  • External HTTP request without auth/sanitization check
  • No nonce checks implemented
  • No capability checks implemented
  • 86% output escaping (potential for 14% unescaped)
Vulnerabilities
None known

Connector GravityForms and MailerLite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Connector GravityForms and MailerLite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

Connector GravityForms and MailerLite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actiongform_loadedconnector-gravityforms-mailerlite.php:28
Maintenance & Trust

Connector GravityForms and MailerLite Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 24, 2023
PHP min version
Downloads23K

Community Trust

Rating82/100
Number of ratings8
Active installs2K
Developer Profile

Connector GravityForms and MailerLite Developer Profile

closemarketing

10 plugins · 8K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connector GravityForms and MailerLite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connector-gravityforms-mailerlite/css/gf-cgfm.css/wp-content/plugins/connector-gravityforms-mailerlite/js/gf-cgfm.js
Script Paths
/wp-content/plugins/connector-gravityforms-mailerlite/js/gf-cgfm.js
Version Parameters
connector-gravityforms-mailerlite/css/gf-cgfm.css?ver=connector-gravityforms-mailerlite/js/gf-cgfm.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_cgfm_settings_page
Data Attributes
data-plugin-slug="connector-gravityforms-mailerlite"data-plugin-path="connector-gravityforms-mailerlite/mailerlite.php"
JS Globals
gf_cgfm
FAQ

Frequently Asked Questions about Connector GravityForms and MailerLite