Contact Form Migrator from Gravity Forms to Formidable Security & Risk Analysis

wordpress.org/plugins/formidable-gravity-forms-importer

Migrate your WordPress contact forms automatically from Gravity Forms to Formidable Forms.

300 active installs v1.03 PHP 7.0+ WP 4.7+ Updated Jul 15, 2025
contact-formformsgravity-formgravity-formsgravityview
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form Migrator from Gravity Forms to Formidable Safe to Use in 2026?

Generally Safe

Score 100/100

Contact Form Migrator from Gravity Forms to Formidable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The formidable-gravity-forms-importer plugin v1.03 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. The code also demonstrates good practices regarding output sanitization, with all identified outputs being properly escaped. The plugin does not appear to perform file operations or external HTTP requests, further reducing its attack surface. The presence of nonce checks and a significant percentage of SQL queries using prepared statements are also positive indicators.

However, the complete absence of capability checks is a notable concern. While the static analysis did not reveal any specific vulnerabilities like taint flows or dangerous functions, the lack of role-based access control could potentially lead to unauthorized actions if an attacker could find a way to interact with the plugin's underlying functionality. The vulnerability history being entirely clear is a positive sign, suggesting the developers have a track record of maintaining a secure plugin, but it doesn't mitigate the current architectural concern of missing capability checks.

In conclusion, the plugin appears to be architecturally sound in terms of common web vulnerabilities like XSS and SQL injection, due to diligent output escaping and prepared statements. The lack of an attack surface is commendable. The primary weakness lies in the absence of capability checks, which is a fundamental security control that should be present for any plugin that might perform sensitive operations. This is the main area for improvement from a security perspective.

Key Concerns

  • Missing capability checks
Vulnerabilities
None known

Contact Form Migrator from Gravity Forms to Formidable Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form Migrator from Gravity Forms to Formidable Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
4 prepared
Unescaped Output
0
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

57% prepared7 total queries

Output Escaping

100% escaped5 total outputs
Attack Surface

Contact Form Migrator from Gravity Forms to Formidable Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedformidable-gravity-forms-importer.php:13
actionadmin_noticesformidable-gravity-forms-importer.php:26
Maintenance & Trust

Contact Form Migrator from Gravity Forms to Formidable Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 15, 2025
PHP min version7.0
Downloads7K

Community Trust

Rating74/100
Number of ratings3
Active installs300
Developer Profile

Contact Form Migrator from Gravity Forms to Formidable Developer Profile

Strategy11 Team

8 plugins · 316K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
844 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form Migrator from Gravity Forms to Formidable

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formidable-gravity-forms-importer/css/admin.css/wp-content/plugins/formidable-gravity-forms-importer/css/importer.css/wp-content/plugins/formidable-gravity-forms-importer/js/importer.js

HTML / DOM Fingerprints

CSS Classes
frm-gravity-importer-wrapgravity-forms-importer-fieldgravity-forms-importer-section
HTML Comments
<!-- Formidable Gravity Forms Importer -->
Data Attributes
data-gf-iddata-frm-type
JS Globals
window.FrmGravityImporter
FAQ

Frequently Asked Questions about Contact Form Migrator from Gravity Forms to Formidable