Enable Turnstile (Cloudflare) for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/enable-turnstile-cloudflare-for-gravity-forms

A lightweight plugin to enable Cloudflare's Turnstile alternative CAPTCHA on your Gravity Forms.

500 active installs v1.7.1 PHP 5.6+ WP 4.1+ Updated Jan 19, 2026
captchacloudflaregravity-formsspam-protectionturnstile
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Enable Turnstile (Cloudflare) for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Enable Turnstile (Cloudflare) for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'enable-turnstile-cloudflare-for-gravity-forms' plugin v1.7.1 demonstrates a strong security posture based on the provided static analysis. The absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces its attack surface. Furthermore, the code signals show excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations and the presence of only one external HTTP request are also positive indicators. The taint analysis showing zero unsanitized paths further strengthens this assessment.

While the plugin's current code appears secure, the absence of nonce checks and capability checks on any potential (though not identified) entry points represents a potential area for concern. If any entry points were to be added or if the analysis missed any, these checks would be crucial for preventing unauthorized actions. The vulnerability history is also clean, with no recorded CVEs, which is a significant strength. However, the limited information about vulnerability history patterns makes it difficult to draw long-term conclusions about the plugin's maintenance and responsiveness to security issues.

In conclusion, the plugin's current version is highly secure according to the static analysis, with robust coding practices in place for SQL, output, and function usage. The primary weakness lies in the lack of explicit authentication/authorization checks on potential, albeit currently unmanifested, entry points, and the limited historical data. Overall, the plugin presents a low-risk profile.

Key Concerns

  • No Nonce Checks
  • No Capability Checks
Vulnerabilities
None known

Enable Turnstile (Cloudflare) for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Enable Turnstile (Cloudflare) for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Enable Turnstile (Cloudflare) for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtergform_field_validationclass.php:39
filtergform_tooltipsclass.php:46
actiongform_field_appearance_settingsclass.php:47
actiongform_loadedss88-gravity-forms-turnstile.php:13
Maintenance & Trust

Enable Turnstile (Cloudflare) for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Enable Turnstile (Cloudflare) for Gravity Forms Developer Profile

Sully

6 plugins · 18K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Enable Turnstile (Cloudflare) for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/enable-turnstile-cloudflare-for-gravity-forms/assets/js/front.js
Script Paths
https://challenges.cloudflare.com/turnstile/v0/api.js?render=explicit
Version Parameters
enable-turnstile-cloudflare-for-gravity-forms/assets/js/front.js?ver=

HTML / DOM Fingerprints

CSS Classes
ginput_container_turnstileginput_container_SS88GFFCT-icon
Data Attributes
data-sitekeydata-timeout-callbackdata-themedata-size
JS Globals
SS88GFFCTSS88TurnstileCallback
FAQ

Frequently Asked Questions about Enable Turnstile (Cloudflare) for Gravity Forms