
Contact Form 7 Gravity Forms Importer Security & Risk Analysis
wordpress.org/plugins/contact-form-7-gravity-formsConvert Contact Form 7 forms into Gravity Forms forms.
Is Contact Form 7 Gravity Forms Importer Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 Gravity Forms Importer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "contact-form-7-gravity-forms" v2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities.
However, the static analysis does reveal a potential weakness in output escaping, with only 30% of total outputs being properly escaped. This suggests a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. The taint analysis shows no flows with unsanitized paths, which is encouraging, but the limited output escaping means this could be a latent risk.
Furthermore, the plugin has no recorded vulnerability history, with zero known CVEs, and no common vulnerability types. This lack of past issues is a positive indicator of the development team's commitment to security. In conclusion, while the plugin demonstrates several strong security practices and a clean vulnerability history, the unaddressed output escaping represents a notable area for improvement and a potential risk that should be monitored.
Key Concerns
- Insufficient output escaping
Contact Form 7 Gravity Forms Importer Security Vulnerabilities
Contact Form 7 Gravity Forms Importer Code Analysis
Output Escaping
Contact Form 7 Gravity Forms Importer Attack Surface
WordPress Hooks 2
Maintenance & Trust
Contact Form 7 Gravity Forms Importer Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 Gravity Forms Importer Alternatives
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
WP Gravity Forms Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
WP Gravity Forms Dynamics CRM
gf-dynamics-crm
Gravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
Gravity Forms Keap Feed
systasis-gf-infusionsoft-feed
Sync form submissions between Gravity Forms and Keap
Integrate SharpSpring and Gravity Forms
integrate-sharpspring-and-gravity-forms
Seamlessly integrate Gravity Forms with SharpSpring ( Constant Contact ). Easily connect all forms on your website, collect lead information into your …
Contact Form 7 Gravity Forms Importer Developer Profile
23 plugins · 14K total installs
How We Detect Contact Form 7 Gravity Forms Importer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-gravity-forms/css/gfcf7-admin.css/wp-content/plugins/contact-form-7-gravity-forms/js/gfcf7-admin.js/wp-content/plugins/contact-form-7-gravity-forms/js/gfcf7-admin.jsHTML / DOM Fingerprints
gfcf7-admindata-gfcf7-form-idGFCF7_Import