Docket Connector Security & Risk Analysis

wordpress.org/plugins/docket-connector

Create invoices within your Docket account from Gravity Forms.

20 active installs v1.1.2 PHP 7.1.0+ WP 5.2+ Updated Feb 22, 2021
e-commerceecommercegravity-formsgravityforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Docket Connector Safe to Use in 2026?

Generally Safe

Score 85/100

Docket Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The docket-connector plugin v1.1.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified critical or high-severity vulnerabilities in its history, coupled with a clean taint analysis and a low attack surface, indicates a generally well-secured plugin. The code signals also reveal good practices such as the consistent use of prepared statements for SQL queries and a high percentage of properly escaped output, which are crucial for preventing common web vulnerabilities.

However, a few areas warrant attention. The presence of an external HTTP request, while not inherently malicious, introduces a potential point of failure or attack vector if the external service is compromised or the data transmitted is not handled securely. Furthermore, while there is one nonce check and one capability check, the analysis indicates a total of zero unprotected entry points, which is excellent. The complete lack of any recorded vulnerabilities in its history is a significant strength, suggesting a proactive approach to security by the developers or a very mature codebase. Overall, the plugin appears robust, with minimal identified risks. The main area for review would be the handling of the external HTTP request to ensure it adheres to best security practices.

Key Concerns

  • External HTTP request present
  • 1 nonce check, but 0 entry points reported as unprotected
  • 1 capability check, but 0 entry points reported as unprotected
  • 93% output escaping is good, but 7% is not
Vulnerabilities
None known

Docket Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Docket Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
27 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

93% escaped29 total outputs
Attack Surface

Docket Connector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticessrc\Bootstrap.php:161
actiontgmpa_registersrc\Bootstrap.php:169
actiongform_loadedsrc\Core\Init.php:96
filtergform_entry_detail_meta_boxessrc\Core\Init.php:97
actiongform_post_payment_completedsrc\Core\Init.php:98
Maintenance & Trust

Docket Connector Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 22, 2021
PHP min version7.1.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Docket Connector Developer Profile

Clifford Paulick

4 plugins · 270 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Docket Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/docket-connector/admin-settings.css/wp-content/plugins/docket-connector/admin-settings.js
Script Paths
/wp-content/plugins/docket-connector/admin-settings.js
Version Parameters
docket-connector/admin-settings.css?ver=docket-connector/admin-settings.js?ver=

HTML / DOM Fingerprints

JS Globals
settingsData
FAQ

Frequently Asked Questions about Docket Connector