
Integration for Engaging Networks and Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gf-engaging-networks-add-onA Gravity Forms Add-On to feed submission data into the Engaging Networks CRM/fundraising/advocacy platform.
Is Integration for Engaging Networks and Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Integration for Engaging Networks and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gf-engaging-networks-add-on" plugin version 2.2.9 demonstrates a generally strong security posture based on the static analysis provided. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code exhibits good practices by using prepared statements for all SQL queries and properly escaping all output. The lack of file operations and external HTTP requests also reduces common vulnerability vectors. The taint analysis reporting zero flows with unsanitized paths further reinforces this positive assessment.
Despite these strengths, there are areas for concern. The plugin has zero nonces checks and zero capability checks. This absence of critical security controls means that any discovered vulnerabilities, even if currently absent, could be significantly more impactful as they would bypass WordPress's built-in permission and authorization mechanisms. The single external HTTP request, while not inherently a vulnerability, represents a potential entry point for issues if the external service is compromised or misbehaves.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a very positive indicator, suggesting either a history of secure development or a lack of deep security auditing. However, without any recorded vulnerabilities, it's difficult to infer patterns of common weakness or strength. In conclusion, while the current code shows excellent adherence to secure coding practices for known threats, the lack of authorization checks presents a significant underlying risk that warrants attention.
Key Concerns
- Missing nonce checks
- Missing capability checks
- External HTTP requests
Integration for Engaging Networks and Gravity Forms Security Vulnerabilities
Integration for Engaging Networks and Gravity Forms Release Timeline
Integration for Engaging Networks and Gravity Forms Code Analysis
SQL Query Safety
Output Escaping
Integration for Engaging Networks and Gravity Forms Attack Surface
WordPress Hooks 3
Maintenance & Trust
Integration for Engaging Networks and Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Integration for Engaging Networks and Gravity Forms Alternatives
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
Connector for Gravity Forms and Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-dynamics-crm
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to dynamics crm Online.
WP Gravity Forms Dynamics CRM
gf-dynamics-crm
Gravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
Caldera Forms CiviCRM
cf-civicrm
Integrate CiviCRM entities with Caldera Forms.
Integration for Engaging Networks and Gravity Forms Developer Profile
9 plugins · 11K total installs
How We Detect Integration for Engaging Networks and Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-engaging-networks-add-on/assets/gf-en.js/wp-content/plugins/gf-engaging-networks-add-on/assets/gf-en.cssassets/gf-en.jsgravityforms-en/assets/gf-en.js?ver=gravityforms-en/assets/gf-en.css?ver=HTML / DOM Fingerprints
gf-notice