
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Security & Risk Analysis
wordpress.org/plugins/gf-heroDisable weekends, past dates and holidays in the Gravity Forms date picker, add date filters and unique IDs - without writing code.
Is Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Safe to Use in 2026?
Generally Safe
Score 100/100Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gf-hero" plugin v1.1.2 exhibits a strong security posture based on the provided static analysis results. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code does not appear to utilize dangerous functions, external HTTP requests, or file operations, which are common vectors for vulnerabilities. The use of prepared statements for all SQL queries and a reasonable percentage of output escaping are also positive indicators of secure coding practices.
The vulnerability history is exceptionally clean, with no recorded CVEs. This lack of historical issues suggests either a very well-maintained codebase or a plugin that has not been a significant target for attackers. The presence of capability checks, even with a low count, indicates some consideration for access control. However, the absence of nonce checks on any potential entry points (though none were identified) is a theoretical gap, as is the fact that not all output is properly escaped, leaving a small window for potential XSS if certain output contexts are vulnerable.
Overall, "gf-hero" v1.1.2 presents as a secure plugin with a minimal attack surface and a clean history. The strengths lie in the lack of identifiable vulnerabilities and the presence of good coding practices like prepared statements. The primary, albeit minor, weaknesses are the incomplete output escaping and the theoretical absence of nonce checks if any hidden entry points were to be discovered. The plugin's security is currently high.
Key Concerns
- Output escaping is not 100% complete
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Security Vulnerabilities
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Code Analysis
Output Escaping
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Attack Surface
WordPress Hooks 17
Maintenance & Trust
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Maintenance & Trust
Maintenance Signals
Community Trust
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Alternatives
Restrict Dates Add-On for Gravity Forms
restrict-dates-add-on-for-gravity-forms
A simple and nice plugin to add date restrict dynamically in gravity forms default date picker field.
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms
advanced-date-time-field
This plugin is a lightweight yet powerful date and time picker designed for popular form builder plugins.
Date Picker for Gravity Forms
date-picker-for-gravity-form
Add a date picker field to Gravity Forms. Set custom date formats, min/max date ranges and more. Upgrade to Pro to disable weekdays, specific dates an …
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Developer Profile
2 plugins · 70 total installs
How We Detect Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-hero/level-1/common.css/wp-content/plugins/gf-hero/level-1/site.css/wp-content/plugins/gf-hero/level-2/common.css/wp-content/plugins/gf-hero/level-2/site.css/wp-content/plugins/gf-hero/level-3/common.css/wp-content/plugins/gf-hero/level-3/site.css/wp-content/plugins/gf-hero/level-4/common.css/wp-content/plugins/gf-hero/level-4/site.css+34 more/wp-content/plugins/gf-hero/base/common.js/wp-content/plugins/gf-hero/base/site.js/wp-content/plugins/gf-hero/level-1/common.js/wp-content/plugins/gf-hero/level-1/site.js/wp-content/plugins/gf-hero/level-2/common.js/wp-content/plugins/gf-hero/level-2/site.js+16 moregf-hero/level-1/common.css?ver=gf-hero/level-1/site.css?ver=gf-hero/level-2/common.css?ver=gf-hero/level-2/site.css?ver=gf-hero/level-3/common.css?ver=gf-hero/level-3/site.css?ver=gf-hero/level-4/common.css?ver=gf-hero/level-4/site.css?ver=gf-hero/level-5/common.css?ver=gf-hero/level-5/site.css?ver=gf-hero/level-6/common.css?ver=gf-hero/level-6/site.css?ver=gf-hero/level-7/common.css?ver=gf-hero/level-7/site.css?ver=gf-hero/level-8/common.css?ver=gf-hero/level-8/site.css?ver=gf-hero/level-9/common.css?ver=gf-hero/level-9/site.css?ver=gf-hero/level-10/common.css?ver=gf-hero/level-10/site.css?ver=gf-hero/base/common.js?ver=gf-hero/base/site.js?ver=gf-hero/level-1/common.js?ver=gf-hero/level-1/site.js?ver=gf-hero/level-2/common.js?ver=gf-hero/level-2/site.js?ver=gf-hero/level-3/common.js?ver=gf-hero/level-3/site.js?ver=gf-hero/level-4/common.js?ver=gf-hero/level-4/site.js?ver=gf-hero/level-5/common.js?ver=gf-hero/level-5/site.js?ver=gf-hero/level-6/common.js?ver=gf-hero/level-6/site.js?ver=gf-hero/level-7/common.js?ver=gf-hero/level-7/site.js?ver=gf-hero/level-8/common.js?ver=gf-hero/level-8/site.js?ver=gf-hero/level-9/common.js?ver=gf-hero/level-9/site.js?ver=gf-hero/level-10/common.js?ver=gf-hero/level-10/site.js?ver=HTML / DOM Fingerprints
tggh-no-jstggh_level