
GF Stripe Extensions Security & Risk Analysis
wordpress.org/plugins/gf-stripe-extensionsAdd Stripe functions to Wordpress including ApplePay, analytics, query transactions, limit payments and payment recovery to Gravity Forms.
Is GF Stripe Extensions Safe to Use in 2026?
Generally Safe
Score 100/100GF Stripe Extensions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gf-stripe-extensions" v2.6.7 plugin exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerability history, there are significant concerns stemming from its attack surface and code signals. A high number of REST API routes (11 out of 11) lack permission callbacks, exposing them to potential unauthorized access and manipulation. Furthermore, the presence of the `passthru` function, a known dangerous function, combined with unsanitized path flows in the taint analysis, indicates a potential for command injection vulnerabilities if user input is not meticulously validated and sanitized. The low percentage of properly escaped output also raises concerns about cross-site scripting (XSS) vulnerabilities.
Key Concerns
- High number of unprotected REST API routes
- Dangerous function 'passthru' used
- Unsanitized path flows in taint analysis
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
GF Stripe Extensions Security Vulnerabilities
GF Stripe Extensions Release Timeline
GF Stripe Extensions Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
GF Stripe Extensions Attack Surface
REST API Routes 11
Shortcodes 2
WordPress Hooks 21
Maintenance & Trust
GF Stripe Extensions Maintenance & Trust
Maintenance Signals
Community Trust
GF Stripe Extensions Alternatives
GF Limit Payments
gf-limit-payments
End subscription payments after a certain number of payments
Unique List For Gravity Forms
gf-unique-list
Add a unique piece of text or code to each gravity form from a predefined list. The plugin keeps track of which have been used and will only include u …
Shortcodes for Gravity Forms
shortcodes-for-gravity-forms
Shortcodes for Gravity Forms adds a column in form list to display form shortcodes in backend.
SV Gravity Forms Enhancer
sv-gravity-forms-enhancer
Improves Gravity Forms in various ways.
Survey Reporting & Data Analysis Report Add-On for Gravity Forms
survey-reporting-data-analysis-report-add-on-for-gravity-forms
This plugin extends the Gravity Forms plugin and adds a reporting tool onto any existing forms.
GF Stripe Extensions Developer Profile
14 plugins · 400 total installs
How We Detect GF Stripe Extensions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-stripe-extensions/assets/css/stripe-extensions.css/wp-content/plugins/gf-stripe-extensions/assets/js/stripe-extensions.js/wp-content/plugins/gf-stripe-extensions/assets/js/stripe-extensions-settings.js/wp-content/plugins/gf-stripe-extensions/assets/js/stripe-extensions.js/wp-content/plugins/gf-stripe-extensions/assets/js/stripe-extensions-settings.jsgf-stripe-extensions/assets/css/stripe-extensions.css?ver=gf-stripe-extensions/assets/js/stripe-extensions.js?ver=gf-stripe-extensions/assets/js/stripe-extensions-settings.js?ver=HTML / DOM Fingerprints
gfse-admin-wrapgfse-sub-settingsdata-gfse-input-typedata-gfse-analytics-form-iddata-gfse-analytics-entry-idgfse_settingsgfse_admin/wp-json/gf-stripe-extensions/v1/settings