
Gravitate Automated Tester Security & Risk Analysis
wordpress.org/plugins/gravitate-automated-testerRun Automated PHP or JS Tests.
Is Gravitate Automated Tester Safe to Use in 2026?
Use With Caution
Score 63/100Gravitate Automated Tester has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'gravitate-automated-tester' plugin, version 1.0.0, presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and performing some capability checks, significant concerns exist, particularly regarding its attack surface and output escaping. The presence of two AJAX handlers without authentication checks represents a critical entry point for potential attacks, especially when combined with a high percentage of improperly escaped output. The taint analysis also reveals flows with unsanitized paths, though no critical or high-severity issues were flagged in this specific analysis, suggesting that existing vulnerabilities might be more subtle or related to improper data handling. The plugin's vulnerability history, including a known medium-severity Cross-Site Scripting (XSS) vulnerability that is currently unpatched, is a major red flag. The fact that the last vulnerability occurred recently and remains unaddressed strongly indicates a lack of proactive security maintenance, increasing the risk of exploitation. In conclusion, while some security foundations are in place, the unpatched vulnerability and the exposed AJAX handlers, coupled with poor output sanitization, create a considerable risk profile for this plugin.
Key Concerns
- Unpatched CVE identified
- AJAX handlers without auth checks (2)
- Significant percentage of unescaped output
- Flows with unsanitized paths detected
- Only 1 nonce check on 4 entry points
Gravitate Automated Tester Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Gravitate Automated Tester <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Gravitate Automated Tester Code Analysis
Output Escaping
Data Flow Analysis
Gravitate Automated Tester Attack Surface
AJAX Handlers 4
WordPress Hooks 6
Maintenance & Trust
Gravitate Automated Tester Maintenance & Trust
Maintenance Signals
Community Trust
Gravitate Automated Tester Alternatives
Editoria11y Accessibility Checker
editoria11y-accessibility-checker
Content accessibility checker written to be intuitive and useful for non-technical authors and editors.
Sa11y, the accessibility quality assurance assistant | Accessibility Checker
sa11y
Geared towards content authors, Sa11y straightforwardly identifies accessibility issues at the source.
Diffy Visual Regression Testing
diffy
Diffy helps to verify plugin updates by taking screenshots of your site before and after update and comparing them. Ideally you expect zero changes a …
Gravitate Automated Tester Developer Profile
1 plugin · 30 total installs
How We Detect Gravitate Automated Tester
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravitate-automated-tester/gravitate-automated-tester/style.css?ver=gravitate-automated-tester/script.js?ver=HTML / DOM Fingerprints
GRAV_TEST_AUTH_KEY