Emercury for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/emercury-for-gravity-forms

Join the 10,000+ customers who use Emercury, an email marketing platform made for lead generators. Sync your customer’s first name, last name, email a …

0 active installs v1.3.1 PHP 7.0+ WP 4.6+ Updated Unknown
add-onemailemercurygravity-formssubscription
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Emercury for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Emercury for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "emercury-for-gravity-forms" v1.3.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events contributing to the attack surface, and crucially, none of these are unprotected, is a significant positive. The code also shows good practices in handling SQL queries, with 100% utilizing prepared statements, and a complete lack of dangerous function usage, file operations, or bundled libraries. However, concerns arise from the relatively low percentage of properly escaped output (43%), indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care before being displayed. The presence of an external HTTP request, while not inherently risky without further context, warrants attention to ensure it is made securely. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong indicator of past security diligence. This suggests that while current code analysis reveals minor areas for improvement, the plugin has historically been maintained with security in mind. Overall, the plugin is in a good state, but the unescaped output is the primary area requiring attention to maintain its secure standing.

Key Concerns

  • Low percentage of output escaping
  • Presence of external HTTP requests
Vulnerabilities
None known

Emercury for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Emercury for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

43% escaped7 total outputs
Attack Surface

Emercury for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergform_entry_detail_meta_boxesclass-gf-emercury.php:191
filterhttp_request_timeoutemercury.php:38
actiongform_loadedemercury.php:45
Maintenance & Trust

Emercury for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Emercury for Gravity Forms Developer Profile

Emercury

5 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Emercury for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/emercury-for-gravity-forms/includes/merge-tags.js/wp-content/plugins/emercury-for-gravity-forms/includes/gf-emercury.js/wp-content/plugins/emercury-for-gravity-forms/includes/gf-emercury.css
Script Paths
/wp-content/plugins/emercury-for-gravity-forms/includes/merge-tags.js/wp-content/plugins/emercury-for-gravity-forms/includes/gf-emercury.js
Version Parameters
emercury-for-gravity-forms/includes/gf-emercury.css?ver=emercury-for-gravity-forms/includes/gf-emercury.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_emercury_lists
JS Globals
gf_emercury_merge_tags
FAQ

Frequently Asked Questions about Emercury for Gravity Forms