Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Security & Risk Analysis

wordpress.org/plugins/gf-hero

Disable weekends, past dates and holidays in the Gravity Forms date picker, add date filters and unique IDs - without writing code.

60 active installs v1.1.2 PHP 7.0+ WP 5.1+ Updated Dec 2, 2025
date-pickerdisable-past-datesgravity-formslimit-datesunique-id
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Safe to Use in 2026?

Generally Safe

Score 100/100

Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "gf-hero" plugin v1.1.2 exhibits a strong security posture based on the provided static analysis results. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code does not appear to utilize dangerous functions, external HTTP requests, or file operations, which are common vectors for vulnerabilities. The use of prepared statements for all SQL queries and a reasonable percentage of output escaping are also positive indicators of secure coding practices.

The vulnerability history is exceptionally clean, with no recorded CVEs. This lack of historical issues suggests either a very well-maintained codebase or a plugin that has not been a significant target for attackers. The presence of capability checks, even with a low count, indicates some consideration for access control. However, the absence of nonce checks on any potential entry points (though none were identified) is a theoretical gap, as is the fact that not all output is properly escaped, leaving a small window for potential XSS if certain output contexts are vulnerable.

Overall, "gf-hero" v1.1.2 presents as a secure plugin with a minimal attack surface and a clean history. The strengths lie in the lack of identifiable vulnerabilities and the presence of good coding practices like prepared statements. The primary, albeit minor, weaknesses are the incomplete output escaping and the theoretical absence of nonce checks if any hidden entry points were to be discovered. The plugin's security is currently high.

Key Concerns

  • Output escaping is not 100% complete
Vulnerabilities
None known

Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
8 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped11 total outputs
Attack Surface

Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_enqueue_scriptsadmin.php:57
filtergform_noconflict_scriptsadmin.php:58
filtergform_noconflict_stylesadmin.php:59
actionwp_headbase\common.php:19
actionadmin_headbase\common.php:20
actionwp_headbase\common.php:64
actionadmin_headbase\common.php:65
filtergform_field_css_classbase\forms.php:20
filtergform_field_contentbase\site.php:27
actionplugins_loadedgf-hero.php:50
actiontggh_after_date_filter_valuelevel-1\admin.php:220
actiongform_field_appearance_settingslevel-1\admin.php:269
actiongform_field_appearance_settingslevel-1\admin.php:270
actiongform_field_standard_settingslevel-1\admin.php:271
actiongform_field_advanced_settingslevel-1\admin.php:272
filtergform_tooltipslevel-1\admin.php:273
actionwp_enqueue_scriptssite.php:36
Maintenance & Trust

Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On Developer Profile

Toro Guapo

2 plugins · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-hero/level-1/common.css/wp-content/plugins/gf-hero/level-1/site.css/wp-content/plugins/gf-hero/level-2/common.css/wp-content/plugins/gf-hero/level-2/site.css/wp-content/plugins/gf-hero/level-3/common.css/wp-content/plugins/gf-hero/level-3/site.css/wp-content/plugins/gf-hero/level-4/common.css/wp-content/plugins/gf-hero/level-4/site.css+34 more
Script Paths
/wp-content/plugins/gf-hero/base/common.js/wp-content/plugins/gf-hero/base/site.js/wp-content/plugins/gf-hero/level-1/common.js/wp-content/plugins/gf-hero/level-1/site.js/wp-content/plugins/gf-hero/level-2/common.js/wp-content/plugins/gf-hero/level-2/site.js+16 more
Version Parameters
gf-hero/level-1/common.css?ver=gf-hero/level-1/site.css?ver=gf-hero/level-2/common.css?ver=gf-hero/level-2/site.css?ver=gf-hero/level-3/common.css?ver=gf-hero/level-3/site.css?ver=gf-hero/level-4/common.css?ver=gf-hero/level-4/site.css?ver=gf-hero/level-5/common.css?ver=gf-hero/level-5/site.css?ver=gf-hero/level-6/common.css?ver=gf-hero/level-6/site.css?ver=gf-hero/level-7/common.css?ver=gf-hero/level-7/site.css?ver=gf-hero/level-8/common.css?ver=gf-hero/level-8/site.css?ver=gf-hero/level-9/common.css?ver=gf-hero/level-9/site.css?ver=gf-hero/level-10/common.css?ver=gf-hero/level-10/site.css?ver=gf-hero/base/common.js?ver=gf-hero/base/site.js?ver=gf-hero/level-1/common.js?ver=gf-hero/level-1/site.js?ver=gf-hero/level-2/common.js?ver=gf-hero/level-2/site.js?ver=gf-hero/level-3/common.js?ver=gf-hero/level-3/site.js?ver=gf-hero/level-4/common.js?ver=gf-hero/level-4/site.js?ver=gf-hero/level-5/common.js?ver=gf-hero/level-5/site.js?ver=gf-hero/level-6/common.js?ver=gf-hero/level-6/site.js?ver=gf-hero/level-7/common.js?ver=gf-hero/level-7/site.js?ver=gf-hero/level-8/common.js?ver=gf-hero/level-8/site.js?ver=gf-hero/level-9/common.js?ver=gf-hero/level-9/site.js?ver=gf-hero/level-10/common.js?ver=gf-hero/level-10/site.js?ver=

HTML / DOM Fingerprints

CSS Classes
tggh-no-js
JS Globals
tggh_level
FAQ

Frequently Asked Questions about Date Filters, Date Picker & Unique IDs for Gravity Forms – Hero Add-On