Date/Time Fields for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/datetime-fields-for-gravityforms

Create a new custom field for "GravityForms" plugin called "Date/Time" field.

200 active installs v1.0 PHP + WP 4.0+ Updated Aug 3, 2019
datedatetimeformsgravity-formstime
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Date/Time Fields for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Date/Time Fields for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the "datetime-fields-for-gravityforms" v1.0 plugin indicates a very strong security posture. There are no identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) that are exposed without proper authentication checks, which is an excellent practice. The code also demonstrates good defensive programming by utilizing prepared statements for all SQL queries and ensuring all outputs are properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and the lack of bundled libraries further contribute to a reduced attack surface.

Taint analysis shows no identified vulnerabilities, and the plugin has no recorded history of CVEs. This suggests that the developers have a good understanding of secure coding practices and have likely maintained a clean codebase over time. The primary concern, albeit a minor one in the context of overall security, is the complete absence of nonce checks and capability checks. While the lack of exposed entry points mitigates the immediate risk, implementing these checks would provide an additional layer of defense should any new entry points be introduced or if the existing ones are ever discovered to have unforeseen vulnerabilities.

In conclusion, this plugin appears to be very secure based on the provided data. The developers have prioritized security by minimizing the attack surface and adhering to best practices for database queries and output handling. The lack of historical vulnerabilities further supports this assessment. The only area for improvement would be the addition of nonce and capability checks for a more robust security framework, even in the absence of immediate threats.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Date/Time Fields for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Date/Time Fields for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Date/Time Fields for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergform_tooltipsclass-gfdatetimefield.php:47
actiongform_field_appearance_settingsclass-gfdatetimefield.php:48
actiongform_loadeddatetimefield.php:13
Maintenance & Trust

Date/Time Fields for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedAug 3, 2019
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Date/Time Fields for Gravity Forms Developer Profile

Gravity Extra

4 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Date/Time Fields for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datetime-fields-for-gravityforms/datetimefield.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Date/Time Fields for Gravity Forms