GF Limit Payments Security & Risk Analysis

wordpress.org/plugins/gf-limit-payments

End subscription payments after a certain number of payments

0 active installs v1.0.2 PHP + WP 4.0.1+ Updated Oct 24, 2023
formsgformsgravitygravity-formsqueries
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GF Limit Payments Safe to Use in 2026?

Generally Safe

Score 85/100

GF Limit Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "gf-limit-payments" v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, and all outputs are properly escaped, indicating good development practices against common vulnerabilities. The absence of file operations and external HTTP requests further reduces the attack surface. Crucially, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of secure development and maintenance.

However, the most significant concern is the complete lack of any authentication or capability checks for any of its entry points. While the current attack surface is zero, this is a direct result of there being no AJAX handlers, REST API routes, shortcodes, or cron events. If any of these were to be introduced in future versions without proper authorization mechanisms, it would create a critical security gap. The plugin also lacks nonce checks, which, in combination with the absence of other checks, presents a potential risk if any interaction points are added.

In conclusion, while the current version is remarkably secure due to its limited functionality and robust coding practices, the absence of any authorization controls is a structural weakness that warrants attention for future development. The plugin is currently safe to use, but future updates must incorporate proper security checks.

Key Concerns

  • No Nonce Checks
  • No Capability Checks
Vulnerabilities
None known

GF Limit Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GF Limit Payments Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

GF Limit Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped10 total outputs
Attack Surface

GF Limit Payments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actiongform_loadedgf-limit-payments.php:24
actiongform_post_payment_callbackgf-limit-payments.php:25
Maintenance & Trust

GF Limit Payments Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.0
Last updatedOct 24, 2023
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GF Limit Payments Developer Profile

jamesdlow

14 plugins · 400 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect GF Limit Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-limit-payments/gf-limit-payments-addon.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about GF Limit Payments