Contact Form 7 Gravity Forms Importer Security & Risk Analysis

wordpress.org/plugins/contact-form-7-gravity-forms

Convert Contact Form 7 forms into Gravity Forms forms.

200 active installs v2.0 PHP + WP 3.3+ Updated Feb 9, 2015
crmformformsgravitygravity-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 Gravity Forms Importer Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 Gravity Forms Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "contact-form-7-gravity-forms" v2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities.

However, the static analysis does reveal a potential weakness in output escaping, with only 30% of total outputs being properly escaped. This suggests a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The taint analysis shows no flows with unsanitized paths, which is encouraging, but the limited output escaping means this could be a latent risk.

Furthermore, the plugin has no recorded vulnerability history, with zero known CVEs, and no common vulnerability types. This lack of past issues is a positive indicator of the development team's commitment to security. In conclusion, while the plugin demonstrates several strong security practices and a clean vulnerability history, the unaddressed output escaping represents a notable area for improvement and a potential risk that should be monitored.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Contact Form 7 Gravity Forms Importer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 Gravity Forms Importer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

30% escaped10 total outputs
Attack Surface

Contact Form 7 Gravity Forms Importer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtergform_addon_navigationcontact-form-7-gravity-forms.php:48
actioninitcontact-form-7-gravity-forms.php:50
Maintenance & Trust

Contact Form 7 Gravity Forms Importer Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedFeb 9, 2015
PHP min version
Downloads16K

Community Trust

Rating54/100
Number of ratings15
Active installs200
Developer Profile

Contact Form 7 Gravity Forms Importer Developer Profile

Zack Katz

23 plugins · 14K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 Gravity Forms Importer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-7-gravity-forms/css/gfcf7-admin.css/wp-content/plugins/contact-form-7-gravity-forms/js/gfcf7-admin.js
Script Paths
/wp-content/plugins/contact-form-7-gravity-forms/js/gfcf7-admin.js

HTML / DOM Fingerprints

CSS Classes
gfcf7-admin
Data Attributes
data-gfcf7-form-id
JS Globals
GFCF7_Import
FAQ

Frequently Asked Questions about Contact Form 7 Gravity Forms Importer