Entries Importing for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/entries-importing-for-gravity-forms

Entries Importing for Gravity Forms

100 active installs v2.6.1 PHP 7.1+ WP 5.0+ Updated Nov 18, 2020
entriesgravityformsimport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Entries Importing for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Entries Importing for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "entries-importing-for-gravity-forms" v2.6.1 exhibits a generally strong security posture, with no reported vulnerabilities or known CVEs, indicating a history of responsible development. The static analysis reveals a minimal attack surface, with no unprotected entry points found across AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, mitigating the risk of SQL injection. However, there are some areas for concern. A significant portion of output (39%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Additionally, the presence of three flows with unsanitized paths, despite not being classified as critical or high severity, suggests a potential for path traversal vulnerabilities or other file system-related exploits. The inclusion of the Guzzle library, while common, necessitates vigilance regarding its version and any known vulnerabilities within it. Overall, the plugin demonstrates good practices in preventing common web vulnerabilities but requires attention to output escaping and path handling to further harden its security.

Key Concerns

  • Unescaped output detected
  • Flows with unsanitized paths
  • Bundled library (Guzzle) may require updates
Vulnerabilities
None known

Entries Importing for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Entries Importing for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
20 escaped
Nonce Checks
3
Capability Checks
2
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

61% escaped33 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
process_csv_upload (src\class-viaentriesimport.php:204)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Entries Importing for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtergform_export_menusrc\class-viaentriesimport.php:25
actiongform_export_page_import_entrysrc\class-viaentriesimport.php:32
actionadmin_noticessrc\class-viaentriesimport.php:34
actiongform_loadedvia-gravityforms-entires-import.php:27
Maintenance & Trust

Entries Importing for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 18, 2020
PHP min version7.1
Downloads9K

Community Trust

Rating100/100
Number of ratings5
Active installs100
Developer Profile

Entries Importing for Gravity Forms Developer Profile

viastudio

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Entries Importing for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/entries-importing-for-gravity-forms/assets/css/style.css/wp-content/plugins/entries-importing-for-gravity-forms/assets/js/script.js
Version Parameters
entries-importing-for-gravity-forms/assets/css/style.css?ver=entries-importing-for-gravity-forms/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_invalid
HTML Comments
<!-- Plugin Name: Entries Importing for Gravity Forms --><!-- Description: Import an exported CSV into a Gravity Forms form -->
Data Attributes
data-plugin-slug="via-gravityforms-entries-import"
JS Globals
var ViaGFEntriesImport
FAQ

Frequently Asked Questions about Entries Importing for Gravity Forms