
Integration for Salsa Engage and Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gf-engage-add-onA Gravity Forms Add-On to feed submission data into the Salsa "Engage" CRM/fundraising/advocacy platform.
Is Integration for Salsa Engage and Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Integration for Salsa Engage and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "gf-engage-add-on" v1.1.5 plugin exhibits a strong security posture with no critical or high-severity issues identified. The absence of reported CVEs and the clean taint analysis results are highly positive indicators. The code demonstrates good practices by using prepared statements for all SQL queries, properly escaping all output, and performing nonce checks on its (limited) entry points. The attack surface is also remarkably small, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, further reducing the potential for exploitation.
However, a notable observation is the complete absence of capability checks. While the current entry points are minimal and potentially protected by WordPress's default authentication mechanisms, relying solely on the absence of an attack surface without explicit capability checks can be a weakness. If the plugin were to be extended or if future versions introduced new entry points, this lack of explicit authorization checks could become a significant security concern. The single external HTTP request is also a minor point of attention, as it represents an external dependency that could potentially be a vector for attacks if not handled securely within the plugin.
Key Concerns
- Missing capability checks on entry points
Integration for Salsa Engage and Gravity Forms Security Vulnerabilities
Integration for Salsa Engage and Gravity Forms Release Timeline
Integration for Salsa Engage and Gravity Forms Code Analysis
SQL Query Safety
Output Escaping
Integration for Salsa Engage and Gravity Forms Attack Surface
WordPress Hooks 5
Maintenance & Trust
Integration for Salsa Engage and Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Integration for Salsa Engage and Gravity Forms Alternatives
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
Connector for Gravity Forms and Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-dynamics-crm
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to dynamics crm Online.
WP Gravity Forms Dynamics CRM
gf-dynamics-crm
Gravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
Caldera Forms CiviCRM
cf-civicrm
Integrate CiviCRM entities with Caldera Forms.
Integration for Salsa Engage and Gravity Forms Developer Profile
9 plugins · 11K total installs
How We Detect Integration for Salsa Engage and Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-engage-add-on/dist/js/gf-engage-admin.js/wp-content/plugins/gf-engage-add-on/dist/js/gf-engage-frontend.jsgf-engage-add-on/dist/js/gf-engage-admin.js?ver=gf-engage-add-on/dist/js/gf-engage-frontend.js?ver=gf-engage-add-on/dist/css/gf-engage-admin.css?ver=gf-engage-add-on/dist/css/gf-engage-frontend.css?ver=HTML / DOM Fingerprints
gf_engage_admin_noticedata-engage_api_clear_cachegf_engage_admin_paramsgf_engage_frontend_params