
Forms: 3rd-Party Resend Gravity Forms Security & Risk Analysis
wordpress.org/plugins/forms-3rdparty-gravity-formsResend Gravity Forms submissions to 3rdparty service when updating entries.
Is Forms: 3rd-Party Resend Gravity Forms Safe to Use in 2026?
Generally Safe
Score 85/100Forms: 3rd-Party Resend Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "forms-3rdparty-gravity-forms" v0.1.2 exhibits a generally strong security posture based on the static analysis. The absence of any recorded vulnerabilities, including CVEs, is a significant positive indicator. Furthermore, the code signals show a commitment to secure coding practices, such as 100% of SQL queries using prepared statements and the presence of nonce checks.
However, there are notable areas for improvement. The most concerning aspect is the very low percentage of properly escaped output (29%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or plugin-generated content may not be adequately sanitized before being displayed to users, potentially allowing attackers to inject malicious scripts.
Despite the lack of identified taint flows, the unescaped output represents a tangible and common threat. The absence of capability checks, while not a direct vulnerability in itself, means that the plugin does not enforce user roles for its entry points. Combined with the limited attack surface, this is less critical but still a weakness that could be exploited if new entry points were added without proper authorization checks. Overall, the plugin is well-maintained with no historical issues, but the output escaping needs immediate attention to mitigate XSS risks.
Key Concerns
- Low output escaping percentage
- No capability checks on entry points
Forms: 3rd-Party Resend Gravity Forms Security Vulnerabilities
Forms: 3rd-Party Resend Gravity Forms Code Analysis
Output Escaping
Forms: 3rd-Party Resend Gravity Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Forms: 3rd-Party Resend Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Forms: 3rd-Party Resend Gravity Forms Alternatives
Integration for Zoho CRM and Zoho Bigin – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-any-form-with-zoho-crm
Connect Zoho CRM and Zoho Bigin. Create Leads, Contacts, Accounts, Deals, and Pipelines from any form submission.
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-hubspot-crm
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with HubSpot CRM.
AAL Connector For LACRM
aal-connector-for-lacrm
Sync Contact Form 7 and Gravity Forms submissions to Less Annoying CRM via the official API.
CRMZT Connector for Zoho by TechArk
crmzt-integration-with-zoho-for-gravity-forms
Integrate Gravity Forms with Zoho CRM to automatically send form submissions as Leads, Contacts, or entries in custom modules.
LeadMachine Connector
leadmachine-connector
Connect your WordPress site to LeadMachine to capture and manage leads seamlessly. Supports native forms and Gravity Forms.
Forms: 3rd-Party Resend Gravity Forms Developer Profile
13 plugins · 5K total installs
How We Detect Forms: 3rd-Party Resend Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forms-3rdparty-gravity-forms/forms-3rdparty-resend-gf.phpHTML / DOM Fingerprints
gf_form_toolbar_f3i_resendwindow.F3iGfResend