
Connector for Gravity Forms and Salesforce Security & Risk Analysis
wordpress.org/plugins/gf-salesforce-crmperksGravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
Is Connector for Gravity Forms and Salesforce Safe to Use in 2026?
Generally Safe
Score 96/100Connector for Gravity Forms and Salesforce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "gf-salesforce-crmperks" v1.5.2 exhibits a mixed security posture. While it demonstrates some good security practices, such as a significant number of nonce and capability checks, and a majority of SQL queries utilizing prepared statements, several concerning aspects are present. The static analysis revealed a single AJAX handler without authentication checks, which represents a direct attack vector. Furthermore, the presence of the `unserialize` function is a red flag for potential deserialization vulnerabilities, especially when combined with the taint analysis showing a high severity flow with unsanitized paths. The vulnerability history reveals a pattern of past exploits including deserialization, open redirects, and XSS, with a recent high-severity vulnerability. While there are currently no unpatched CVEs, the recurring types of vulnerabilities and the findings in the static and taint analysis suggest a need for ongoing vigilance and careful code review.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: unserialize
- High severity taint flow with unsanitized paths
- Past high severity CVE
- Past medium severity CVEs
- Bundled library (Select2)
Connector for Gravity Forms and Salesforce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Gravity Forms Salesforce <= 1.5.1 - Unauthenticated PHP Object Injection
WP Gravity Forms Salesforce <= 1.4.7 - Open Redirect
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
Connector for Gravity Forms and Salesforce Release Timeline
Connector for Gravity Forms and Salesforce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Connector for Gravity Forms and Salesforce Attack Surface
AJAX Handlers 1
WordPress Hooks 36
Maintenance & Trust
Connector for Gravity Forms and Salesforce Maintenance & Trust
Maintenance Signals
Community Trust
Connector for Gravity Forms and Salesforce Alternatives
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
cf7-salesforce
Send Contact Form 7, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submissions to salesforce.
Account Engagement
pardot
Integrate Account Engagement with WordPress: easily track visitors, embed forms and dynamic content in pages and posts, or use the forms or dynamic co …
Outfunnel: Web Visitor Tracking & CRM Integration
outfunnel
Track which leads visit your website and automatically sync WordPress form submissions to Pipedrive, HubSpot, Copper, or Salesforce.
Object Sync for Salesforce
object-sync-for-salesforce
Object Sync for Salesforce maps and syncs data between Salesforce objects and WordPress objects.
Object Data Sync for Salesforce Integration with WP, Woo, Gravity, WPForms, Ninja, CF7 & more
object-data-sync-for-salesforce
Integrate Salesforce with WordPress to map and sync WordPress data like users, posts, WooCommerce orders, forms, and events with Salesforce standard a …
Connector for Gravity Forms and Salesforce Developer Profile
32 plugins · 105K total installs
How We Detect Connector for Gravity Forms and Salesforce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-salesforce-crmperks/css/style.css/wp-content/plugins/gf-salesforce-crmperks/js/main.js/wp-content/plugins/gf-salesforce-crmperks/js/main.jsgf-salesforce-crmperks/css/style.css?ver=gf-salesforce-crmperks/js/main.js?ver=HTML / DOM Fingerprints
vx_noticevx_m<!-- Installing Gravity Forms Salesforce Plugin version=<!-- Loading Admin page --><!-- Loading Form Editor --><!-- Loading Settings Page -->+2 moredata-idwindow.vxg_salesforce_obj