GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Security & Risk Analysis

wordpress.org/plugins/gf-gourl-add-on

This plugin enables you to use the GoUrl.io payment gateway and accept bitcoin and other altcoins directly on your Gravity Forms powered custom forms …

20 active installs v1.0.4 PHP + WP 4.0+ Updated Dec 4, 2025
altcoinsbitcoincryptocurrencygravity-formspayment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The gf-gourl-add-on plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known vulnerabilities or CVEs in its history, suggesting a generally secure development process and diligent patching. It also performs nonce checks on its entry points. However, a significant concern is the presence of one AJAX handler that lacks authentication checks, creating a potential entry point for unauthorized actions. Furthermore, a notable weakness lies in the output escaping, where only 33% of outputs are properly escaped, leaving room for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without proper sanitization.

The static analysis reveals a limited attack surface, with only one entry point identified. The absence of critical or high-severity taint flows is also a positive indicator. However, the 67% of unsafely escaped outputs, coupled with the unprotected AJAX handler, are the primary areas of concern. The lack of recorded vulnerabilities is reassuring but does not negate the identified code-level risks. In conclusion, while the plugin has a clean vulnerability history and uses secure SQL practices, the unprotected AJAX endpoint and inadequate output escaping represent concrete security risks that should be addressed to improve its overall security.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
Vulnerabilities
None known

GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
4 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped12 total outputs
Attack Surface
1 unprotected

GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_gf_dismiss_gourl_menuclass-gf-gourl.php:863
WordPress Hooks 10
actionwpclass-gf-gourl.php:3
filtergform_disable_post_creationclass-gf-gourl.php:48
filtergform_disable_notificationclass-gf-gourl.php:49
actiongform_payment_statusclass-gf-gourl.php:874
actiongform_payment_dateclass-gf-gourl.php:875
actiongform_payment_transaction_idclass-gf-gourl.php:876
actiongform_payment_amountclass-gf-gourl.php:877
actiongform_after_update_entryclass-gf-gourl.php:878
actiongform_loadedgourl.php:34
filtergform_currenciesgourl.php:48
Maintenance & Trust

GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms Developer Profile

mohsin.id

6 plugins · 15K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-gourl-add-on/assets/css/gf_gourl_admin.css/wp-content/plugins/gf-gourl-add-on/assets/js/gf_gourl_admin.js
Script Paths
/wp-content/plugins/gf-gourl-add-on/assets/js/gf_gourl_admin.js
Version Parameters
gf-gourl-add-on/assets/css/gf_gourl_admin.css?ver=gf-gourl-add-on/assets/js/gf_gourl_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_gourl_settings_section
HTML Comments
<!-- GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms -->
Data Attributes
data-gourl-plugin-namedata-gourl-plugin-version
JS Globals
GF_GoUrl
FAQ

Frequently Asked Questions about GoUrl Bitcoin Altcoin Payment Gateway For Gravity Forms