Drip for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/drip-gravity-forms

Integrates Gravity Forms with personalized Email Marketing tool Drip.

500 active installs v2.1.2 PHP + WP 3.0.1+ Updated Nov 11, 2025
dripemailgetdripgravity-formsgravityforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Drip for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Drip for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "drip-gravity-forms" v2.1.2 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a potentially stable codebase. However, significant concerns arise from its attack surface and output handling. The presence of two AJAX handlers without any authentication or capability checks creates a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionalities, which is a major security risk. Additionally, the complete lack of output escaping is highly problematic, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is rendered directly to the browser.

Key Concerns

  • AJAX handlers without authentication checks
  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Drip for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Drip for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped4 total outputs
Attack Surface
2 unprotected

Drip for Gravity Forms Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_gf_dismiss_drip_menuincludes\class-addon.php:189
authwp_ajax_gf_get_drip_field_guideincludes\class-addon.php:191
WordPress Hooks 2
filtergform_addon_navigationincludes\class-addon.php:206
actionplugins_loadedincludes\class-gfp-drip.php:57
Maintenance & Trust

Drip for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 11, 2025
PHP min version
Downloads15K

Community Trust

Rating74/100
Number of ratings6
Active installs500
Developer Profile

Drip for Gravity Forms Developer Profile

getdrip

3 plugins · 4K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Drip for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/drip-gravity-forms/js/gf-drip-admin.js/wp-content/plugins/drip-gravity-forms/css/gf-drip-admin.css
Script Paths
/wp-content/plugins/drip-gravity-forms/js/gf-drip-admin.js
Version Parameters
drip-gravity-forms/js/gf-drip-admin.js?ver=drip-gravity-forms/css/gf-drip-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
gf_drip_section_title
Data Attributes
data-drip-id
JS Globals
gfdrip_admin_params
FAQ

Frequently Asked Questions about Drip for Gravity Forms