Integration for Salsa Engage and Gravity Forms Security & Risk Analysis

wordpress.org/plugins/gf-engage-add-on

A Gravity Forms Add-On to feed submission data into the Salsa "Engage" CRM/fundraising/advocacy platform.

50 active installs v1.1.5 PHP 5.6.38+ WP 3.6+ Updated Dec 3, 2025
crmformsintegration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Integration for Salsa Engage and Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for Salsa Engage and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "gf-engage-add-on" v1.1.5 plugin exhibits a strong security posture with no critical or high-severity issues identified. The absence of reported CVEs and the clean taint analysis results are highly positive indicators. The code demonstrates good practices by using prepared statements for all SQL queries, properly escaping all output, and performing nonce checks on its (limited) entry points. The attack surface is also remarkably small, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, further reducing the potential for exploitation.

However, a notable observation is the complete absence of capability checks. While the current entry points are minimal and potentially protected by WordPress's default authentication mechanisms, relying solely on the absence of an attack surface without explicit capability checks can be a weakness. If the plugin were to be extended or if future versions introduced new entry points, this lack of explicit authorization checks could become a significant security concern. The single external HTTP request is also a minor point of attention, as it represents an external dependency that could potentially be a vector for attacks if not handled securely within the plugin.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Integration for Salsa Engage and Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Integration for Salsa Engage and Gravity Forms Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Integration for Salsa Engage and Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped8 total outputs
Attack Surface

Integration for Salsa Engage and Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesclass-gfengage-admin-notice.php:37
actiongform_post_payment_completedclass-gfengage.php:415
actiongform_update_payment_statusclass-gfengage.php:416
actiongform_loadedgravityforms-engage.php:13
actiongform_loadedgravityforms-engage.php:14
Maintenance & Trust

Integration for Salsa Engage and Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.6.38
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Integration for Salsa Engage and Gravity Forms Developer Profile

cornershop

9 plugins · 11K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Salsa Engage and Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/gf-engage-add-on/dist/js/gf-engage-admin.js/wp-content/plugins/gf-engage-add-on/dist/js/gf-engage-frontend.js
Version Parameters
gf-engage-add-on/dist/js/gf-engage-admin.js?ver=gf-engage-add-on/dist/js/gf-engage-frontend.js?ver=gf-engage-add-on/dist/css/gf-engage-admin.css?ver=gf-engage-add-on/dist/css/gf-engage-frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
gf_engage_admin_notice
Data Attributes
data-engage_api_clear_cache
JS Globals
gf_engage_admin_paramsgf_engage_frontend_params
FAQ

Frequently Asked Questions about Integration for Salsa Engage and Gravity Forms