
Sort Export for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gf-sort-exportControl (and persist) the order of the fields during the export of entries.
Is Sort Export for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Sort Export for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gf-sort-export" plugin version 1.1.2 exhibits a mixed security posture. On the positive side, it avoids dangerous functions, uses prepared statements for all SQL queries, and properly escapes all output. It also has no recorded vulnerability history, suggesting a generally stable and well-maintained codebase in the past. However, a significant concern arises from its attack surface, specifically the two AJAX handlers that lack authentication checks. This means any authenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if the handlers are not designed with strict internal authorization logic.
The taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, warrant attention. These flows could represent potential entry points for malicious input that is not adequately validated or cleaned before being used in downstream operations. Given the lack of nonce checks on these AJAX handlers, these unsanitized paths could be leveraged by attackers to execute arbitrary code or manipulate data within the WordPress environment.
In conclusion, while the plugin demonstrates good practices in core areas like SQL handling and output sanitization, the unprotected AJAX endpoints and the identified unsanitized taint flows represent tangible security risks. The absence of known CVEs is a positive indicator, but the current analysis highlights vulnerabilities that could be exploited in the absence of further security controls. The plugin is not inherently insecure due to its basic coding practices, but the exposed entry points require careful consideration and mitigation.
Key Concerns
- AJAX handlers without authentication checks
- Taint flows with unsanitized paths
- Missing nonce checks on AJAX handlers
Sort Export for Gravity Forms Security Vulnerabilities
Sort Export for Gravity Forms Code Analysis
Bundled Libraries
Data Flow Analysis
Sort Export for Gravity Forms Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Sort Export for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Sort Export for Gravity Forms Alternatives
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
Order Export & Order Import for WooCommerce
order-import-export-for-woocommerce
The best order export import plugin for WooCommerce. Easily import and export WooCommerce orders and WooCommerce coupons using CSV.
Sort Export for Gravity Forms Developer Profile
1 plugin · 50 total installs
How We Detect Sort Export for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-sort-export/public/js/gf-sort-export.jquery.js/wp-content/plugins/gf-sort-export/public/js/gf-sort-export.jquery.min.js/wp-content/plugins/gf-sort-export/public/css/gf-sort-export.css/wp-content/plugins/gf-sort-export/public/css/gf-sort-export.min.css/wp-content/plugins/gf-sort-export/public/js/gf-sort-export.jquery.js/wp-content/plugins/gf-sort-export/public/js/gf-sort-export.jquery.min.jsgf-sort-export/public/js/gf-sort-export.jquery.js?ver=gf-sort-export/public/css/gf-sort-export.css?ver=HTML / DOM Fingerprints
window.gf_sort_export/wp-json/gf-sort-export/store-order/wp-json/gf-sort-export/get-order