
EngageBay for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/engagebay-gravity-formsThis plugin integrates Gravity Forms with EngageBay allowing form submissions to be automatically sent to user’s EngageBay account.
Is EngageBay for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100EngageBay for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "engagebay-gravity-forms" plugin version 3.1.7 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or exploitable attack surface components (AJAX, REST API, shortcodes, cron events) is highly positive. The code appears to adhere to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping output. The plugin also makes several external HTTP requests, which themselves are not inherently a security risk without further context, but it is good that there are no other apparent weaknesses.
The vulnerability history further reinforces this positive assessment, with no known CVEs recorded for this plugin. This lack of historical vulnerabilities, combined with the clean static analysis, suggests a well-maintained and secure codebase. While the absence of nonce and capability checks is noted, in the context of zero identified entry points and zero unprotected entry points, this is not an immediate concern. However, it's a detail that can be a risk if new entry points are introduced in future versions without proper checks.
In conclusion, the "engagebay-gravity-forms" plugin version 3.1.7 appears to be very secure. The strengths lie in its lack of dangerous code constructs and its clean vulnerability history. The only minor weakness is the absence of explicit nonce and capability checks, which, given the current lack of attack surface, is not a significant risk but something to monitor for future updates.
EngageBay for Gravity Forms Security Vulnerabilities
EngageBay for Gravity Forms Code Analysis
EngageBay for Gravity Forms Attack Surface
WordPress Hooks 5
Maintenance & Trust
EngageBay for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
EngageBay for Gravity Forms Alternatives
Gravity Pre-submission Confirmation
gravity-pre-submission-confirmation
A WordPress plugin which adds a pre-submission confirmation page to your Graviy forms where users can preview their entered data before they submit it …
GF No Duplicates
gf-no-duplicates
Prevents duplicate Gravity Forms submissions caused by the same POST request sent more than once.
WP Gravity Forms Zoho CRM and Bigin
gf-zoho
Gravity Forms Zoho CRM Add-On Sends Gravity Forms entries to Zoho CRM and Bigin.
Global Payments SecureSubmit Addon for Gravity Forms
heartland-secure-submit-addon-for-gravity-forms
SecureSubmit allows merchants to take PCI-Friendly Credit Card payments with Gravity Forms using Global Payments Payment Gateway.
Spark GF Failed Submissions
spark-gf-failed-submissions
Track failed form submissions and get notified when they reach a customisable threshold. Requires Gravity Forms.
EngageBay for Gravity Forms Developer Profile
6 plugins · 400 total installs
How We Detect EngageBay for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/engagebay-gravity-forms/images/engagebay_logo.png/wp-content/plugins/engagebay-gravity-forms/js/engagebay.jsHTML / DOM Fingerprints
data-engagebaygfaddonsettings