Gravity Forms Prevent Duplicates Security & Risk Analysis

wordpress.org/plugins/gf-prevent-duplicates

Simply prevent duplicate submissions by blocking the submit button while submitting

100 active installs v1.2.1 PHP + WP 4.6+ Updated Feb 17, 2020
doubleduplicatesformsgravityprevent
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms Prevent Duplicates Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms Prevent Duplicates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "gf-prevent-duplicates" plugin, version 1.2.1, exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the plugin demonstrates good practices by using prepared statements for all its SQL queries and a high percentage of properly escaped output. The presence of a nonce check and a decent percentage of capability checks also contribute positively to its security. The vulnerability history is completely clean, with no recorded CVEs, indicating a well-maintained and secure codebase historically.

However, there are areas that, while not presenting immediate critical risks based on this snapshot, could be improved for enhanced security. The attack surface is reported as zero entry points, which is excellent, but this should be continually monitored as the plugin evolves. The complete lack of taint analysis flows, while appearing positive, could also mean that the analysis itself was limited in scope or that the plugin's functionality doesn't lend itself to such flows, making it harder to definitively rule out potential vulnerabilities without deeper manual review or more comprehensive static analysis tools. The 0 capability checks are a slight concern as they offer less granular access control.

In conclusion, this plugin appears to be very secure with no known vulnerabilities and good coding practices. The primary strengths lie in its avoidance of risky functions and its robust handling of database interactions. The absence of significant code signals for concern is a strong indicator of its safety. The clean vulnerability history further reinforces confidence in its security. The only minor points for potential improvement revolve around the complete lack of capability checks, which could be implemented for more robust access control.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

Gravity Forms Prevent Duplicates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms Prevent Duplicates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
62 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped73 total outputs
Attack Surface

Gravity Forms Prevent Duplicates Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsgf-prevent-duplicates.php:26
actionadmin_menugf-prevent-duplicates.php:31
Maintenance & Trust

Gravity Forms Prevent Duplicates Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedFeb 17, 2020
PHP min version
Downloads4K

Community Trust

Rating90/100
Number of ratings2
Active installs100
Developer Profile

Gravity Forms Prevent Duplicates Developer Profile

termel

14 plugins · 800 total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Prevent Duplicates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-prevent-duplicates/js/gfpreventduplicates.js
Script Paths
/wp-content/plugins/gf-prevent-duplicates/js/gfpreventduplicates.js

HTML / DOM Fingerprints

JS Globals
gfpd_stringsgfpd_strings.button_messagegfpd_strings.currently_uploadinggfpd_strings.excluded_form_ids
FAQ

Frequently Asked Questions about Gravity Forms Prevent Duplicates