
WP Gravity Forms Keap/Infusionsoft Security & Risk Analysis
wordpress.org/plugins/gf-infusionsoftGravity Forms Keap/infusionsoft Add-on sends Gravity Forms entries to infusionsoft/Keap CRM.
Is WP Gravity Forms Keap/Infusionsoft Safe to Use in 2026?
Generally Safe
Score 96/100WP Gravity Forms Keap/Infusionsoft has a strong security track record. Known vulnerabilities have been patched promptly.
The gf-infusionsoft plugin v1.2.7 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL prepared statements and capability checks, significant concerns arise from its attack surface and taint analysis results. The presence of an unprotected AJAX handler is a critical weakness, as it provides an entry point for unauthenticated attackers. The taint analysis reveals one high-severity flow with unsanitized data, which could potentially lead to various injection attacks if exploited. The plugin's vulnerability history, with three past CVEs including high and medium severity issues like 'Open Redirect', 'Deserialization of Untrusted Data', and 'Cross-site Scripting', indicates a pattern of past security oversights. Although no CVEs are currently unpatched, this history suggests a need for ongoing vigilance and robust security development practices. The plugin's strengths in using prepared statements and capability checks are commendable, but the unprotected AJAX handler and high-severity taint flow overshadow these positive aspects, demanding immediate attention.
Key Concerns
- Unprotected AJAX handler present
- High severity taint flow with unsanitized paths
- Past high severity CVEs detected
- Past medium severity CVEs detected
- Significant amount of SQL queries
- Some outputs not properly escaped
WP Gravity Forms Keap/Infusionsoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Gravity Forms Keap/Infusionsoft <= 1.2.6 - Open Redirect
Gravity Forms Keap/Infusionsoft <= 1.2.3 - Unauthenticated PHP Object Injection
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
WP Gravity Forms Keap/Infusionsoft Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Gravity Forms Keap/Infusionsoft Attack Surface
AJAX Handlers 1
WordPress Hooks 34
Maintenance & Trust
WP Gravity Forms Keap/Infusionsoft Maintenance & Trust
Maintenance Signals
Community Trust
WP Gravity Forms Keap/Infusionsoft Alternatives
Gravity Forms Keap Feed
systasis-gf-infusionsoft-feed
Sync form submissions between Gravity Forms and Keap
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
WP Gravity Forms Keap/Infusionsoft Developer Profile
32 plugins · 105K total installs
How We Detect WP Gravity Forms Keap/Infusionsoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-infusionsoft/includes/plugin-pages.php/wp-content/plugins/gf-infusionsoft/includes/crmperks-gf.php/wp-content/plugins/gf-infusionsoft/includes/edit-form.php/wp-content/plugins/gf-infusionsoft/pro/add-ons.php/wp-content/plugins/gf-infusionsoft/wp/crmperks-notices.php/wp-content/plugins/gf-infusionsoft/includes/install.phpgf-infusionsoft/style.css?ver=gf-infusionsoft/script.js?ver=HTML / DOM Fingerprints
vx_noticevx_msg<!-- exp --><!-- Install Gravity Forms Notice (plugin row) --><!-- admin_screen_message function. --><!-- Gravity forms status -->+2 moredata-idvxg_infusionsoftvxcf_plugin_api