
WP Gravity Forms Dynamics CRM Security & Risk Analysis
wordpress.org/plugins/gf-dynamics-crmGravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
Is WP Gravity Forms Dynamics CRM Safe to Use in 2026?
Generally Safe
Score 98/100WP Gravity Forms Dynamics CRM has a strong security track record. Known vulnerabilities have been patched promptly.
The gf-dynamics-crm v1.1.6 plugin exhibits a mixed security posture. While it demonstrates good practices in several areas, including a significant number of nonce and capability checks, and a respectable percentage of SQL prepared statements and output escaping, critical security concerns are present. The static analysis reveals a concerning single unprotected AJAX handler, which represents a direct entry point for potential attacks. Furthermore, the taint analysis indicates a flow with unsanitized paths classified as high severity, suggesting a potential vulnerability that could be exploited if not properly addressed. The plugin's vulnerability history shows two past medium-severity issues, one related to open redirects and the other to cross-site scripting. While currently no vulnerabilities are unpatched, this history, combined with the current code signals, suggests a pattern of past weaknesses that require diligent attention. The presence of an unprotected AJAX handler and a high-severity unsanitized taint flow are particularly noteworthy risks that need immediate investigation and remediation, despite the plugin's otherwise decent security hygiene in certain aspects.
Key Concerns
- Unprotected AJAX handler
- High severity taint flow with unsanitized path
- Past medium severity vulnerabilities (2 total)
WP Gravity Forms Dynamics CRM Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Gravity Forms Dynamics CRM <= 1.1.4 - Open Redirect
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
WP Gravity Forms Dynamics CRM Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Gravity Forms Dynamics CRM Attack Surface
AJAX Handlers 1
WordPress Hooks 33
Maintenance & Trust
WP Gravity Forms Dynamics CRM Maintenance & Trust
Maintenance Signals
Community Trust
WP Gravity Forms Dynamics CRM Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
WP Gravity Forms Dynamics CRM Developer Profile
32 plugins · 105K total installs
How We Detect WP Gravity Forms Dynamics CRM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-dynamics-crm/assets/css/gs-gf-dynamics.css/wp-content/plugins/gf-dynamics-crm/assets/js/gs-gf-dynamics.js/wp-content/plugins/gf-dynamics-crm/assets/js/gs-gf-dynamics-new.jsgf-dynamics-crm/assets/css/gs-gf-dynamics.css?ver=gf-dynamics-crm/assets/js/gs-gf-dynamics.js?ver=gf-dynamics-crm/assets/js/gs-gf-dynamics-new.js?ver=HTML / DOM Fingerprints
gs_gf_dynamics_contentgs_gf_dynamics_popupgs_gf_dynamics_popup_contentgs_gf_dynamics_loadinggs_gf_dynamics_main_wrapper<!-- gs_gf_dynamics_popup --><!-- gs_gf_dynamics_popup_content --><!-- gs_gf_dynamics_loading --><!-- gs_gf_dynamics_main_wrapper -->data-id='gs_gf_dynamics_id'data-id='gs_gf_dynamics_action'gs_gf_dynamics_params