Gravity Forms – Tab Index Security & Risk Analysis

wordpress.org/plugins/custom-tabindex-gravity-forms-add-on

Gravity Forms Add On. Adds custom tabindex field to the "Advanced" tab for form fields.

100 active installs v1.0.1 PHP + WP 3.8+ Updated Dec 2, 2014
devdeveloperprofileprofilertools
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gravity Forms – Tab Index Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms – Tab Index has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of the "custom-tabindex-gravity-forms-add-on" v1.0.1 plugin indicates a very strong security posture. The code appears to have a minimal attack surface with zero entry points identified, and all present components, if any, are noted as being protected by authentication. Crucially, there are no detected dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations, external HTTP requests, nonce checks, and capability checks also contributes to this positive assessment. The taint analysis shows no identified flows with unsanitized data, reinforcing the impression of secure coding practices. The vulnerability history is equally impressive, with zero known CVEs recorded at any severity level. This suggests a plugin that has either been developed with security as a high priority or has not yet been subjected to extensive public scrutiny for vulnerabilities. The strengths of this plugin lie in its apparent lack of exploitable code paths and its clean vulnerability record. However, the absolute absence of any detected entry points, dangerous functions, or even simple checks like nonces in a real-world plugin might warrant a closer look to ensure the static analysis was exhaustive, though based solely on the provided data, the plugin appears exceptionally secure.

Vulnerabilities
None known

Gravity Forms – Tab Index Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms – Tab Index Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Gravity Forms – Tab Index Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actiongform_field_advanced_settingsgravityforms-tabindex.php:27
actiongform_editor_jsgravityforms-tabindex.php:46
filtergform_tooltipsgravityforms-tabindex.php:67
actiongform_field_inputgravityforms-tabindex.php:76
Maintenance & Trust

Gravity Forms – Tab Index Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 2, 2014
PHP min version
Downloads5K

Community Trust

Rating82/100
Number of ratings7
Active installs100
Developer Profile

Gravity Forms – Tab Index Developer Profile

Brett

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms – Tab Index

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-tabindex-gravity-forms-add-on/gform_tabindex.js
Script Paths
/wp-content/plugins/custom-tabindex-gravity-forms-add-on/gform_tabindex.js
Version Parameters
custom-tabindex-gravity-forms-add-on/gform_tabindex.js?ver=

HTML / DOM Fingerprints

CSS Classes
tabindex_setting
Data Attributes
field_tabindex
JS Globals
fieldSettings
FAQ

Frequently Asked Questions about Gravity Forms – Tab Index