Date Time Field Add-On for Gravity Form Security & Risk Analysis

wordpress.org/plugins/gf-datetime-field-add-on

A date-time add-on for Gravity Forms with custom date time format.

1K active installs v1.3.6 PHP 7.4+ WP 4.0+ Updated Dec 14, 2025
addondatedatetimegravity-formtime
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Date Time Field Add-On for Gravity Form Safe to Use in 2026?

Generally Safe

Score 100/100

Date Time Field Add-On for Gravity Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of gf-datetime-field-add-on v1.3.6 reveals a plugin with an extremely limited attack surface, showing zero AJAX handlers, REST API routes, shortcodes, or cron events. This absence of common entry points is a strong indicator of good security design. Furthermore, the code analysis shows no dangerous functions, no file operations, no external HTTP requests, and importantly, all SQL queries are properly prepared. This demonstrates a commitment to preventing common web vulnerabilities like SQL injection.

However, a notable concern arises from the output escaping. With 15 total outputs and only 60% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means user-supplied or dynamic data might be rendered on a page without adequate sanitization, allowing attackers to inject malicious scripts. The complete absence of nonce checks and capability checks on potential (though currently non-existent) entry points, while less critical with zero entry points, could become a risk if new functionality is added without proper security considerations.

The plugin's vulnerability history is clean, with zero recorded CVEs. This, combined with the strong static analysis findings regarding SQL and dangerous functions, suggests a historically well-maintained and secure plugin. The primary weakness identified is the insufficient output escaping, which represents a tangible risk. In conclusion, while the plugin exhibits excellent practices in preventing injection attacks and maintaining a minimal attack surface, the XSS risk due to poor output escaping warrants attention.

Key Concerns

  • Output escaping is only 60% proper
Vulnerabilities
None known

Date Time Field Add-On for Gravity Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Date Time Field Add-On for Gravity Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped15 total outputs
Attack Surface

Date Time Field Add-On for Gravity Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actiongform_loadedgf-datetime-field-add-on.php:15
actiongform_field_standard_settingsincludes\class-awaiswp-datetime-field-settings.php:19
actiongform_editor_jsincludes\class-awaiswp-datetime-field-settings.php:20
filtergform_tooltipsincludes\class-awaiswp-datetime-field-settings.php:22
filtergform_pre_renderincludes\class-awaiswp-datetime-field-settings.php:23
Maintenance & Trust

Date Time Field Add-On for Gravity Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 14, 2025
PHP min version7.4
Downloads12K

Community Trust

Rating90/100
Number of ratings2
Active installs1K
Developer Profile

Date Time Field Add-On for Gravity Form Developer Profile

Awais

3 plugins · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Date Time Field Add-On for Gravity Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-datetime-field-add-on/assets/css/datetimepicker.min.css/wp-content/plugins/gf-datetime-field-add-on/assets/js/datetimepicker.min.js/wp-content/plugins/gf-datetime-field-add-on/assets/js/gform_datetime_field.js
Script Paths
/wp-content/plugins/gf-datetime-field-add-on/assets/js/datetimepicker.min.js/wp-content/plugins/gf-datetime-field-add-on/assets/js/gform_datetime_field.js
Version Parameters
gf-datetime-field-add-on/assets/css/datetimepicker.min.css?ver=gf-datetime-field-add-on/assets/js/datetimepicker.min.js?ver=gf-datetime-field-add-on/assets/js/gform_datetime_field.js?ver=

HTML / DOM Fingerprints

CSS Classes
datetime_format_value_setting
Data Attributes
field_datetime_format_value
JS Globals
fieldSettings
FAQ

Frequently Asked Questions about Date Time Field Add-On for Gravity Form