Rest API For Cross Platform Support with Gravity Forms Security & Risk Analysis

wordpress.org/plugins/gf-rest-api-for-cross-platform

Create a custom API for Gravity Forms to support cross-platform entries from frameworks like React, AngularJS, and other platforms.

0 active installs v1.0.1 PHP 7.0+ WP 6.2+ Updated Jun 12, 2025
api-for-angular-integrationapi-for-react-integrationgravity-formsrestapi
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rest API For Cross Platform Support with Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Rest API For Cross Platform Support with Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

Based on the static analysis, "gf-rest-api-for-cross-platform" v1.0.1 exhibits a strong security posture with no identified critical or high-severity vulnerabilities in its attack surface or taint analysis. The absence of any known CVEs further reinforces this positive outlook. The plugin demonstrates good development practices by utilizing prepared statements for all its SQL queries and properly escaping most of its output. The limited number of entry points and the absence of exposed AJAX handlers or REST API routes without permission callbacks are commendable.

However, there are areas for improvement. The complete lack of nonce checks and capability checks across all potential entry points represents a significant concern. While the current analysis shows no exploitable flows, this absence creates a latent risk, as any future introduction of functionality without proper authorization checks could be easily exploited. The single file operation also warrants attention to ensure it's handled securely, though its context isn't detailed in the provided data.

In conclusion, the plugin is currently in a good security state, free from known vulnerabilities and employing secure coding practices for database interactions and output handling. The primary weakness lies in the foundational security of its entry points, which currently lack essential authorization and integrity checks. Addressing this would significantly strengthen its overall security.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Unescaped output (5% of total)
Vulnerabilities
None known

Rest API For Cross Platform Support with Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Rest API For Cross Platform Support with Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

95% escaped19 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wot_formapi_code_generator_page (includes\wot-form-api-custom-functions.php:44)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Rest API For Cross Platform Support with Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitgf-rest-api-for-cross-platform.php:50
filtergform_form_settings_menuincludes\wot-form-api-custom-functions.php:30
actiongform_form_settings_page_wot_formapi_code_generatorincludes\wot-form-api-custom-functions.php:43
actionadmin_initincludes\wot-form-api-custom-functions.php:203
actionrest_api_initincludes\wot-form-api-custom-functions.php:267
Maintenance & Trust

Rest API For Cross Platform Support with Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 12, 2025
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Rest API For Cross Platform Support with Gravity Forms Developer Profile

Weboccult Technologies Pvt Ltd

8 plugins · 550 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rest API For Cross Platform Support with Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wotfrpi/v1
FAQ

Frequently Asked Questions about Rest API For Cross Platform Support with Gravity Forms