
Country and State Selection Addon for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gforms-addon-for-country-and-state-selectionCountry and State Selection Addon for Gravity Forms lets you easily add dynamic country and state dropdown fields to your Gravity Forms.
Is Country and State Selection Addon for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Country and State Selection Addon for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "gforms-addon-for-country-and-state-selection" v1.2 presents a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in its handling of SQL queries, using prepared statements exclusively, and a reasonable percentage of output escaping, the lack of authentication checks on all identified entry points creates a substantial attack surface.
The static analysis reveals 4 AJAX handlers, and alarmingly, all 4 lack authorization checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure. The absence of taint analysis flows and file operations, alongside zero external HTTP requests, are positive indicators, suggesting no immediate risks in these specific areas. Furthermore, the plugin's history of zero recorded CVEs is a positive sign, implying a generally stable codebase or diligent patching by developers/users in the past.
However, the unprotected AJAX handlers are a critical weakness that overshadows the positive aspects. The lack of nonces and capability checks on these handlers directly exposes them to various attack vectors. While the vulnerability history is clean, it doesn't negate the inherent risks introduced by the exposed attack surface. A balanced conclusion is that the plugin has some good internal coding practices regarding data handling, but its external security is significantly compromised by its unprotected AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
- Low output escaping percentage
Country and State Selection Addon for Gravity Forms Security Vulnerabilities
Country and State Selection Addon for Gravity Forms Release Timeline
Country and State Selection Addon for Gravity Forms Code Analysis
Output Escaping
Country and State Selection Addon for Gravity Forms Attack Surface
AJAX Handlers 4
WordPress Hooks 7
Maintenance & Trust
Country and State Selection Addon for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Country and State Selection Addon for Gravity Forms Alternatives
Auto Save Progress for Gravity Forms
auto-save-progress-for-gravity-forms
Automatically save Gravity Forms progress to browser localStorage. Recover user data if page is refreshed or closed.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
Country and State Selection Addon for Gravity Forms Developer Profile
8 plugins · 5K total installs
How We Detect Country and State Selection Addon for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gforms-addon-for-country-and-state-selection/assets/js/fields.js/wp-content/plugins/gforms-addon-for-country-and-state-selection/assets/js/admin.js/wp-content/plugins/gforms-addon-for-country-and-state-selection/assets/css/admin.cssassets/js/fields.jsassets/js/admin.jsgforms-addon-for-country-and-state-selection/assets/js/fields.js?ver=gforms-addon-for-country-and-state-selection/assets/js/admin.js?ver=gforms-addon-for-country-and-state-selection/assets/css/admin.css?ver=HTML / DOM Fingerprints
field_default_valuefield_state_valuefield_default_valuefield_state_valuegfcws_addon_script_jsgfcws_addon_admin_js