Integration for Engaging Networks and Gravity Forms Security & Risk Analysis

wordpress.org/plugins/gf-engaging-networks-add-on

A Gravity Forms Add-On to feed submission data into the Engaging Networks CRM/fundraising/advocacy platform.

70 active installs v2.2.9 PHP 5.6+ WP 3.6+ Updated Dec 3, 2025
crmformsintegration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration for Engaging Networks and Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for Engaging Networks and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "gf-engaging-networks-add-on" plugin version 2.2.9 demonstrates a generally strong security posture based on the static analysis provided. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code exhibits good practices by using prepared statements for all SQL queries and properly escaping all output. The lack of file operations and external HTTP requests also reduces common vulnerability vectors. The taint analysis reporting zero flows with unsanitized paths further reinforces this positive assessment.

Despite these strengths, there are areas for concern. The plugin has zero nonces checks and zero capability checks. This absence of critical security controls means that any discovered vulnerabilities, even if currently absent, could be significantly more impactful as they would bypass WordPress's built-in permission and authorization mechanisms. The single external HTTP request, while not inherently a vulnerability, represents a potential entry point for issues if the external service is compromised or misbehaves.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a very positive indicator, suggesting either a history of secure development or a lack of deep security auditing. However, without any recorded vulnerabilities, it's difficult to infer patterns of common weakness or strength. In conclusion, while the current code shows excellent adherence to secure coding practices for known threats, the lack of authorization checks presents a significant underlying risk that warrants attention.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests
Vulnerabilities
None known

Integration for Engaging Networks and Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Integration for Engaging Networks and Gravity Forms Release Timeline

v2.2.9Current
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.4
v2.1.3
v2.1.2
Code Analysis
Analyzed Mar 16, 2026

Integration for Engaging Networks and Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped5 total outputs
Attack Surface

Integration for Engaging Networks and Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergform_settings_save_buttonclass-gfen.php:321
actiongform_loadedgravityforms-en.php:20
actionadmin_noticesgravityforms-en.php:21
Maintenance & Trust

Integration for Engaging Networks and Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.6
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Integration for Engaging Networks and Gravity Forms Developer Profile

cornershop

9 plugins · 11K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Engaging Networks and Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-engaging-networks-add-on/assets/gf-en.js/wp-content/plugins/gf-engaging-networks-add-on/assets/gf-en.css
Script Paths
assets/gf-en.js
Version Parameters
gravityforms-en/assets/gf-en.js?ver=gravityforms-en/assets/gf-en.css?ver=

HTML / DOM Fingerprints

CSS Classes
gf-notice
FAQ

Frequently Asked Questions about Integration for Engaging Networks and Gravity Forms