Connector for Gravity Forms and Salesforce Security & Risk Analysis

wordpress.org/plugins/gf-salesforce-crmperks

Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.

1K active installs v1.5.3 PHP 5.3+ WP 4.7+ Updated Apr 14, 2026
gravity-forms-salesforcegravity-forms-salesforce-crmgravity-forms-salesforce-integrationsalesforcesalesforce-wordpress-gravity-forms
96
A · Safe
CVEs total3
Unpatched0
Last CVEAug 8, 2025
Safety Verdict

Is Connector for Gravity Forms and Salesforce Safe to Use in 2026?

Generally Safe

Score 96/100

Connector for Gravity Forms and Salesforce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Aug 8, 2025Updated 1mo ago
Risk Assessment

The plugin "gf-salesforce-crmperks" v1.5.2 exhibits a mixed security posture. While it demonstrates some good security practices, such as a significant number of nonce and capability checks, and a majority of SQL queries utilizing prepared statements, several concerning aspects are present. The static analysis revealed a single AJAX handler without authentication checks, which represents a direct attack vector. Furthermore, the presence of the `unserialize` function is a red flag for potential deserialization vulnerabilities, especially when combined with the taint analysis showing a high severity flow with unsanitized paths. The vulnerability history reveals a pattern of past exploits including deserialization, open redirects, and XSS, with a recent high-severity vulnerability. While there are currently no unpatched CVEs, the recurring types of vulnerabilities and the findings in the static and taint analysis suggest a need for ongoing vigilance and careful code review.

Key Concerns

  • Unprotected AJAX handler
  • Dangerous function: unserialize
  • High severity taint flow with unsanitized paths
  • Past high severity CVE
  • Past medium severity CVEs
  • Bundled library (Select2)
Vulnerabilities
3 published

Connector for Gravity Forms and Salesforce Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-60180high · 8.1Deserialization of Untrusted Data

Gravity Forms Salesforce <= 1.5.1 - Unauthenticated PHP Object Injection

Aug 8, 2025 Patched in 1.5.2 (135d)
CVE-2025-30953medium · 6.1URL Redirection to Untrusted Site ('Open Redirect')

WP Gravity Forms Salesforce <= 1.4.7 - Open Redirect

Jun 5, 2025 Patched in 1.4.8 (43d)
WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-gf-salesforce-crmperksmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.2.6 (880d)
Code Analysis
Analyzed Mar 16, 2026

Connector for Gravity Forms and Salesforce Code Analysis

Dangerous Functions
1
Raw SQL Queries
8
17 prepared
Unescaped Output
114
421 escaped
Nonce Checks
20
Capability Checks
30
File Operations
3
External Requests
3
Bundled Libraries
1

Dangerous Functions Found

unserialize$value=unserialize($value, array('allowed_classes' => false));gf-salesforce-crmperks.php:573

Bundled Libraries

Select2

SQL Query Safety

68% prepared25 total queries

Output Escaping

79% escaped535 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<plugin-pages> (includes\plugin-pages.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Connector for Gravity Forms and Salesforce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_vxg_sales_review_dismisswp\crmperks-notices.php:19
WordPress Hooks 36
actionplugins_loadedgf-salesforce-crmperks.php:62
actionadmin_noticesgf-salesforce-crmperks.php:78
actiongform_entry_createdgf-salesforce-crmperks.php:128
actiongform_post_add_entrygf-salesforce-crmperks.php:130
actiongform_after_update_entrygf-salesforce-crmperks.php:132
actiongform_update_statusgf-salesforce-crmperks.php:134
actiongform_post_payment_completedgf-salesforce-crmperks.php:138
actiongform_after_submissiongf-salesforce-crmperks.php:140
actiongform_post_add_subscription_paymentgf-salesforce-crmperks.php:141
filtergform_confirmationgf-salesforce-crmperks.php:144
filtergform_custom_merge_tagsgf-salesforce-crmperks.php:146
filtergform_replace_merge_tagsgf-salesforce-crmperks.php:147
actioninitgf-salesforce-crmperks.php:151
actiongform_entry_detail_content_afterincludes\crmperks-gf.php:11
filtergform_tooltipsincludes\edit-form.php:14
actiongform_editor_jsincludes\edit-form.php:15
actiongform_field_standard_settingsincludes\edit-form.php:16
actionadmin_headincludes\edit-form.php:17
filtergform_admin_pre_renderincludes\edit-form.php:25
filtergform_pre_renderincludes\edit-form.php:26
filtergform_tooltipsincludes\plugin-pages.php:37
filtergform_logging_supportedincludes\plugin-pages.php:41
actiongform_form_settings_menuincludes\plugin-pages.php:42
filteradmin_menuincludes\plugin-pages.php:44
actiongform_post_note_addedincludes\plugin-pages.php:46
actiongform_pre_note_deletedincludes\plugin-pages.php:47
actiongform_entry_detail_sidebar_middleincludes\plugin-pages.php:51
actiongform_entry_infoincludes\plugin-pages.php:52
actionadmin_noticesincludes\plugin-pages.php:54
filterplugin_action_linksincludes\plugin-pages.php:55
actionadd_section_vxg_salesforcewp\crmperks-notices.php:14
actionadd_section_mapping_vxg_salesforcewp\crmperks-notices.php:15
filterplugin_row_metawp\crmperks-notices.php:16
filteradmin_footer_textwp\crmperks-notices.php:22
filtermenu_links_vxg_salesforcewp\crmperks-notices.php:23
filtertab_contents_vxg_salesforcewp\crmperks-notices.php:24
Maintenance & Trust

Connector for Gravity Forms and Salesforce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version5.3
Downloads88K

Community Trust

Rating98/100
Number of ratings134
Active installs1K
Developer Profile

Connector for Gravity Forms and Salesforce Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
339 days
View full developer profile
Detection Fingerprints

How We Detect Connector for Gravity Forms and Salesforce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-salesforce-crmperks/css/style.css/wp-content/plugins/gf-salesforce-crmperks/js/main.js
Script Paths
/wp-content/plugins/gf-salesforce-crmperks/js/main.js
Version Parameters
gf-salesforce-crmperks/css/style.css?ver=gf-salesforce-crmperks/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
vx_noticevx_m
HTML Comments
<!-- Installing Gravity Forms Salesforce Plugin version=<!-- Loading Admin page --><!-- Loading Form Editor --><!-- Loading Settings Page -->+2 more
Data Attributes
data-id
JS Globals
window.vxg_salesforce_obj
FAQ

Frequently Asked Questions about Connector for Gravity Forms and Salesforce