
WP Gravity Forms Constant Contact Plugin Security & Risk Analysis
wordpress.org/plugins/gf-constant-contactgravity forms constant contact addon Requires at least: 3.8 Tested up to: 6.9 Stable tag: 1.1.3 Version: 1.1.3 Requires PHP: 5.
Is WP Gravity Forms Constant Contact Plugin Safe to Use in 2026?
Generally Safe
Score 94/100WP Gravity Forms Constant Contact Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "gf-constant-contact" plugin version 1.1.3 presents a mixed security posture. While the plugin demonstrates several good security practices, such as a high percentage of SQL queries using prepared statements and robust nonce and capability checks, there are significant concerns that elevate its risk profile.
The static analysis reveals a single AJAX handler that lacks authentication checks, creating a direct attack vector. The presence of the `unserialize` function, a known dangerous function, is a critical red flag, especially when coupled with potential input sources that could be controlled by an attacker. Although the taint analysis shows no identified flows with unsanitized paths in this specific version, the historical vulnerability data is highly concerning.
The plugin has a history of 3 known CVEs, with 2 classified as high severity, including deserialization, open redirect, and XSS vulnerabilities. The fact that the last reported vulnerability was in the very near future (2025-08-08) suggests either a recent discovery of past issues or a potential ongoing development/reporting problem. This historical pattern of critical vulnerabilities, particularly around deserialization, strongly indicates a recurring tendency for insecure handling of user-supplied data, even if current taint analysis doesn't reflect it. While the current version has no unpatched CVEs, the historical context and the identified unsecured entry point warrant caution.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: unserialize
- History of high severity vulnerabilities (2)
- History of medium severity vulnerabilities (1)
- Bundled library: Select2
WP Gravity Forms Constant Contact Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Gravity Forms Constant Contact <= 1.1.2 - Unauthenticated PHP Object Injection
WP Gravity Forms Constant Contact Plugin <= 1.1.0 - Open Redirect
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
WP Gravity Forms Constant Contact Plugin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
WP Gravity Forms Constant Contact Plugin Attack Surface
AJAX Handlers 1
WordPress Hooks 34
Maintenance & Trust
WP Gravity Forms Constant Contact Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WP Gravity Forms Constant Contact Plugin Alternatives
Gravity Forms Constant Contact
gravity-forms-constant-contact
Add contacts to your Constant Contact mailing list when they submit a Gravity Forms form.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Constant Contact Forms
constant-contact-forms
The official Constant Contact plugin adds a contact form to your WordPress site to quickly capture information from visitors.
WP Gravity Forms Constant Contact Plugin Developer Profile
32 plugins · 105K total installs
How We Detect WP Gravity Forms Constant Contact Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-constant-contact/css/main.css/wp-content/plugins/gf-constant-contact/js/main.js/wp-content/plugins/gf-constant-contact/css/admin.css/wp-content/plugins/gf-constant-contact/js/main.jsgf-constant-contact/css/main.css?ver=gf-constant-contact/js/main.js?ver=gf-constant-contact/css/admin.css?ver=HTML / DOM Fingerprints
vx_noticevxg_ccontactvxcf_plugin_api