Gravity Forms ConvertKit Add-On Security & Risk Analysis

wordpress.org/plugins/convertkit-gravity-forms

ConvertKit is an email marketing platform for capturing leads from your WordPress blog.

800 active installs v1.4.3 PHP 5.6.20+ WP 5.0+ Updated Apr 3, 2024
captureconvertkitemailembed-formmarketing
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gravity Forms ConvertKit Add-On Safe to Use in 2026?

Generally Safe

Score 92/100

Gravity Forms ConvertKit Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "convertkit-gravity-forms" plugin, version 1.4.3, exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, all output appears to be properly escaped, and the taint analysis shows no unsanitized paths, indicating a low risk of code injection or data leakage through these vectors. The plugin also has no recorded vulnerabilities in its history, suggesting a history of secure development or diligent patching.

However, a significant concern arises from the complete lack of any identified security checks, including nonce checks, capability checks, or authentication checks on entry points. While the current attack surface is reported as zero, this absence of protective measures means that if any new entry points were introduced in future updates, they would likely be unprotected. The reported zero AJAX handlers, REST API routes, and shortcodes are positive but could be a static report artifact if the plugin does not utilize these features. The overall lack of explicit security checks, despite the current clean bill of health, represents a potential weakness if the plugin's functionality evolves.

In conclusion, the plugin currently appears to be secure due to the absence of vulnerabilities and robust coding practices in areas like output escaping and SQL handling. The primary weakness lies in the lack of explicit security checks across its codebase, which, while not currently exploitable due to a seemingly minimal attack surface, presents a latent risk for future development. This plugin demonstrates good current security but could benefit from more robust, explicit security measures to ensure continued safety.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • No AJAX handlers with auth checks found
  • No REST API routes with permission callbacks found
Vulnerabilities
None known

Gravity Forms ConvertKit Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms ConvertKit Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

Gravity Forms ConvertKit Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initincludes\class-ckgf-notices.php:24
actionadmin_noticesincludes\class-ckgf-notices.php:44
actionconvertkit_gravity_forms_initialize_adminincludes\class-ckgf-notices.php:77
filtergform_form_settings_fieldsincludes\class-gfconvertkit.php:166
filtergform_enqueue_scriptsincludes\class-gfconvertkit.php:169
actiongform_loadedincludes\class-wp-ckgf.php:44
actioninitincludes\class-wp-ckgf.php:47
actioninitincludes\class-wp-ckgf.php:50
Maintenance & Trust

Gravity Forms ConvertKit Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 3, 2024
PHP min version5.6.20
Downloads57K

Community Trust

Rating66/100
Number of ratings3
Active installs800
Developer Profile

Gravity Forms ConvertKit Add-On Developer Profile

Kit

2 plugins · 41K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
164 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms ConvertKit Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/convertkit-gravity-forms/assets/css/ckgf-admin.css/wp-content/plugins/convertkit-gravity-forms/assets/js/ckgf-admin.js/wp-content/plugins/convertkit-gravity-forms/assets/js/ckgf-frontend.js
Script Paths
/wp-content/plugins/convertkit-gravity-forms/assets/js/ckgf-admin.js/wp-content/plugins/convertkit-gravity-forms/assets/js/ckgf-frontend.js
Version Parameters
convertkit-gravity-forms/assets/css/ckgf-admin.css?ver=convertkit-gravity-forms/assets/js/ckgf-admin.js?ver=convertkit-gravity-forms/assets/js/ckgf-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ckgf-field-settingckgf-field-mapping
HTML Comments
<!-- The Creator Network Recommendations script is ONLY shown if it is enabled on the ConvertKit account and is configured to work with this form. --><!-- ConvertKit Gravity Forms Settings --><!-- ConvertKit Field Mapping -->
Data Attributes
data-ckgf-fielddata-ckgf-targetdata-ckgf-sourcedata-field-iddata-field-typedata-field-label
JS Globals
WP_CKGFGFConvertKitckgf_plugin_urlckgf_plugin_version
FAQ

Frequently Asked Questions about Gravity Forms ConvertKit Add-On