
Date Time Field Add-On for Gravity Form Security & Risk Analysis
wordpress.org/plugins/gf-datetime-field-add-onA date-time add-on for Gravity Forms with custom date time format.
Is Date Time Field Add-On for Gravity Form Safe to Use in 2026?
Generally Safe
Score 100/100Date Time Field Add-On for Gravity Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of gf-datetime-field-add-on v1.3.6 reveals a plugin with an extremely limited attack surface, showing zero AJAX handlers, REST API routes, shortcodes, or cron events. This absence of common entry points is a strong indicator of good security design. Furthermore, the code analysis shows no dangerous functions, no file operations, no external HTTP requests, and importantly, all SQL queries are properly prepared. This demonstrates a commitment to preventing common web vulnerabilities like SQL injection.
However, a notable concern arises from the output escaping. With 15 total outputs and only 60% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means user-supplied or dynamic data might be rendered on a page without adequate sanitization, allowing attackers to inject malicious scripts. The complete absence of nonce checks and capability checks on potential (though currently non-existent) entry points, while less critical with zero entry points, could become a risk if new functionality is added without proper security considerations.
The plugin's vulnerability history is clean, with zero recorded CVEs. This, combined with the strong static analysis findings regarding SQL and dangerous functions, suggests a historically well-maintained and secure plugin. The primary weakness identified is the insufficient output escaping, which represents a tangible risk. In conclusion, while the plugin exhibits excellent practices in preventing injection attacks and maintaining a minimal attack surface, the XSS risk due to poor output escaping warrants attention.
Key Concerns
- Output escaping is only 60% proper
Date Time Field Add-On for Gravity Form Security Vulnerabilities
Date Time Field Add-On for Gravity Form Code Analysis
Output Escaping
Date Time Field Add-On for Gravity Form Attack Surface
WordPress Hooks 5
Maintenance & Trust
Date Time Field Add-On for Gravity Form Maintenance & Trust
Maintenance Signals
Community Trust
Date Time Field Add-On for Gravity Form Alternatives
Date/Time Fields for Gravity Forms
datetime-fields-for-gravityforms
Create a new custom field for "GravityForms" plugin called "Date/Time" field.
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms
advanced-date-time-field
This plugin is a lightweight yet powerful date and time picker designed for popular form builder plugins.
Blog Time
blog-time
Display the time according to your blog via an admin toolbar widget, a sidebar widget, and/or a template tag.
Timeline Express – Date – Time Add-On
timeline-express-date-time-add-on
Assign and display times alongside the announcement dates in Timeline Express announcements.
STARTEND Subscription Add-On for GravityForms
startend-subscription-add-on-for-gravityforms
Description: STARTEND is a Gravity Forms Add-on that allows you to set one or many future start dates and customize an automated end date for your Gra …
Date Time Field Add-On for Gravity Form Developer Profile
3 plugins · 1K total installs
How We Detect Date Time Field Add-On for Gravity Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-datetime-field-add-on/assets/css/datetimepicker.min.css/wp-content/plugins/gf-datetime-field-add-on/assets/js/datetimepicker.min.js/wp-content/plugins/gf-datetime-field-add-on/assets/js/gform_datetime_field.js/wp-content/plugins/gf-datetime-field-add-on/assets/js/datetimepicker.min.js/wp-content/plugins/gf-datetime-field-add-on/assets/js/gform_datetime_field.jsgf-datetime-field-add-on/assets/css/datetimepicker.min.css?ver=gf-datetime-field-add-on/assets/js/datetimepicker.min.js?ver=gf-datetime-field-add-on/assets/js/gform_datetime_field.js?ver=HTML / DOM Fingerprints
datetime_format_value_settingfield_datetime_format_valuefieldSettings