
Gravity Forms Borgun Add-On Security & Risk Analysis
wordpress.org/plugins/gf-borgun-add-onTake payments in your gravity forms using the Borgun Gateway
Is Gravity Forms Borgun Add-On Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms Borgun Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gf-borgun-add-on plugin version 1.0.0 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. There is also no history of known vulnerabilities (CVEs), which suggests a level of diligence in past development or infrequent discovery of issues.
However, significant concerns arise from the static analysis. The plugin exposes one unprotected AJAX handler, representing a direct attack vector. The complete absence of nonce checks and capability checks on this handler further exacerbates this risk, making it vulnerable to Cross-Site Request Forgery (CSRF) and unauthorized function execution. Additionally, a substantial portion of output is not properly escaped, raising the risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any taint analysis results in this version also means that potential data injection or path traversal vulnerabilities might have been missed.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unprotected AJAX endpoint coupled with missing security checks (nonces, capabilities) and insufficient output escaping creates a notable security weakness. The clean vulnerability history is a positive indicator, but it does not negate the immediate risks identified in the code analysis.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks on AJAX handler
- Missing capability checks on AJAX handler
- Insufficient output escaping
- No taint analysis results
Gravity Forms Borgun Add-On Security Vulnerabilities
Gravity Forms Borgun Add-On Code Analysis
SQL Query Safety
Output Escaping
Gravity Forms Borgun Add-On Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Gravity Forms Borgun Add-On Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms Borgun Add-On Alternatives
PayU GPO Payment for WooCommerce
woo-payu-payment-gateway
PayU fast online payments for WooCommerce. Banks, BLIK, credit or debit cards, Installments, Apple Pay, Google Pay.
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
Stripe Payment Forms by WP Simple Pay – Accept Credit Card Payments + Subscriptions with Stripe
stripe
🤩 Accept Stripe payments and recurring subscriptions on your WordPress using WP Simple Pay, the best Stripe payments plugin! 🚀
Asaas Gateway for WooCommerce
woo-asaas
Take transparent credit card and bank ticket payment checkouts on your store using Asaas.
Payment Gateway of PayPal for WooCommerce
express-checkout-paypal-payment-gateway-for-woocommerce
Enable faster checkout with PayPal for WooCommerce. Add PayPal Express/PayPal Standard gateways that accept PayPal, Pay Later, debit & credit cards.
Gravity Forms Borgun Add-On Developer Profile
4 plugins · 220 total installs
How We Detect Gravity Forms Borgun Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-borgun-add-on/borgun.php/wp-content/plugins/gf-borgun-add-on/class-gf-borgun.phpgf-borgun-add-on/borgun.php?ver=gf-borgun-add-on/class-gf-borgun.php?ver=HTML / DOM Fingerprints
looking for feed created by legacy versionsonly one feed per form is supported (left for backwards compatibility)data-gf_borgun_merchant_iddata-gf_borgun_payment_gateway_iddata-gf_borgun_secret_keywindow.gf_borgun_merchant_idwindow.gf_borgun_payment_gateway_idwindow.gf_borgun_secret_key