
WP Gravity Forms Zendesk Security & Risk Analysis
wordpress.org/plugins/gf-zendeskGravity Forms Zendesk Add-on sends Gravity Forms entries to Zendesk.
Is WP Gravity Forms Zendesk Safe to Use in 2026?
Generally Safe
Score 98/100WP Gravity Forms Zendesk has a strong security track record. Known vulnerabilities have been patched promptly.
The 'gf-zendesk' plugin v1.1.4 presents a mixed security posture. On the positive side, it utilizes prepared statements for a good majority of its SQL queries and has a relatively high percentage of properly escaped output, indicating an effort towards secure coding practices. The plugin also includes a substantial number of nonce and capability checks, which are crucial for preventing unauthorized actions.
However, there are significant concerns stemming from the static analysis. The presence of an unprotected AJAX handler represents a critical attack vector, as it could be exploited by unauthenticated users. The taint analysis revealing a flow with unsanitized paths, even if not classified as critical or high severity in this specific instance, is a red flag that points to potential injection vulnerabilities. The history of two medium-severity vulnerabilities, specifically related to 'Open Redirect' and 'Cross-site Scripting', further amplifies these concerns, suggesting a recurring pattern of input sanitization and output encoding weaknesses in past versions.
While the plugin has no currently unpatched CVEs, the historical vulnerabilities and the identified unprotected entry point suggest that ongoing vigilance and careful review of new code are necessary. The plugin has strengths in its use of prepared statements and output escaping, but the unprotected AJAX handler and past vulnerability patterns warrant caution.
Key Concerns
- Unprotected AJAX handler found
- Taint flow with unsanitized path
- 2 medium severity CVEs historically
WP Gravity Forms Zendesk Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Gravity Forms Zendesk <= 1.1.2 - Open Redirect
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
WP Gravity Forms Zendesk Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Gravity Forms Zendesk Attack Surface
AJAX Handlers 1
WordPress Hooks 34
Maintenance & Trust
WP Gravity Forms Zendesk Maintenance & Trust
Maintenance Signals
Community Trust
WP Gravity Forms Zendesk Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
WP Gravity Forms Zendesk Developer Profile
32 plugins · 105K total installs
How We Detect WP Gravity Forms Zendesk
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-zendesk/css/style.css/wp-content/plugins/gf-zendesk/js/script.js/wp-content/plugins/gf-zendesk/js/custom.js/wp-content/plugins/gf-zendesk/pro/plugin-api.js/wp-content/plugins/gf-zendesk/js/script.js/wp-content/plugins/gf-zendesk/js/custom.jsgf-zendesk/css/style.css?ver=gf-zendesk/js/script.js?ver=gf-zendesk/js/custom.js?ver=gf-zendesk/pro/plugin-api.js?ver=HTML / DOM Fingerprints
vx_notice<!-- exit if accessed directly --><!-- plugin starting point. will load appropriate files --><!-- install plugin --><!-- exit if accessed directly -->+5 moredata-id="gravity"data-id="gravity"window.vxg_zendesk_obj