
Gravity Forms Confirmation Page List Security & Risk Analysis
wordpress.org/plugins/gf-confirmation-page-listAllows you see which Confirmation Pages used in each Gravity Forms. Easily to follow up forms !
Is Gravity Forms Confirmation Page List Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms Confirmation Page List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gf-confirmation-page-list" plugin v1.0.0 exhibits a seemingly strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the lack of dangerous functions, SQL queries, file operations, external HTTP requests, and the use of prepared statements for any database interactions are positive indicators of secure coding practices. The absence of vulnerability history further suggests a clean track record.
However, a critical concern arises from the output escaping analysis, where 100% of outputs are not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The complete lack of nonce checks and capability checks, coupled with zero identified taint flows, might be a consequence of the limited attack surface. However, even with a small attack surface, these fundamental security mechanisms should be in place to protect against potential future vulnerabilities or emergent attack vectors. The plugin's current security is heavily reliant on its limited functionality rather than robust security implementations.
Key Concerns
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
Gravity Forms Confirmation Page List Security Vulnerabilities
Gravity Forms Confirmation Page List Code Analysis
Output Escaping
Gravity Forms Confirmation Page List Attack Surface
WordPress Hooks 2
Maintenance & Trust
Gravity Forms Confirmation Page List Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms Confirmation Page List Alternatives
Sliced Invoices & Gravity Forms
sliced-invoices-gravity-forms
Create an invoice or quote request form using Gravity Forms. Each form entry then creates a quote (or an invoice) using the Sliced Invoices plugin.
Gravity Forms Keap Feed
systasis-gf-infusionsoft-feed
Sync form submissions between Gravity Forms and Keap
Gravity Forms Disable Autofill Add-On
gravity-forms-disable-autofill-add-on
Disable the browser's ability to autofill forms and input fields on selected Gravity Forms. Ideal for forms with sensitive information and provid …
Integration for Gravity Forms with Zoho CRM
integration-for-gravity-forms-and-zoho
Integration for Gravity Forms with Zoho CRM is a Zoho CRM integration plugin for WordPress that makes it really simple to send your Gravity forms dire …
Emercury for Gravity Forms
emercury-for-gravity-forms
Join the 10,000+ customers who use Emercury, an email marketing platform made for lead generators. Sync your customer’s first name, last name, email a …
Gravity Forms Confirmation Page List Developer Profile
3 plugins · 420 total installs
How We Detect Gravity Forms Confirmation Page List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.