Gravitate Automated Tester Security & Risk Analysis

wordpress.org/plugins/gravitate-automated-tester

Run Automated PHP or JS Tests.

30 active installs v1.4.5 PHP + WP 3.5+ Updated Jun 24, 2016
automated-testinggravitate
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Gravitate Automated Tester Safe to Use in 2026?

Use With Caution

Score 63/100

Gravitate Automated Tester has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 9yr ago
Risk Assessment

The 'gravitate-automated-tester' plugin, version 1.0.0, presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and performing some capability checks, significant concerns exist, particularly regarding its attack surface and output escaping. The presence of two AJAX handlers without authentication checks represents a critical entry point for potential attacks, especially when combined with a high percentage of improperly escaped output. The taint analysis also reveals flows with unsanitized paths, though no critical or high-severity issues were flagged in this specific analysis, suggesting that existing vulnerabilities might be more subtle or related to improper data handling. The plugin's vulnerability history, including a known medium-severity Cross-Site Scripting (XSS) vulnerability that is currently unpatched, is a major red flag. The fact that the last vulnerability occurred recently and remains unaddressed strongly indicates a lack of proactive security maintenance, increasing the risk of exploitation. In conclusion, while some security foundations are in place, the unpatched vulnerability and the exposed AJAX handlers, coupled with poor output sanitization, create a considerable risk profile for this plugin.

Key Concerns

  • Unpatched CVE identified
  • AJAX handlers without auth checks (2)
  • Significant percentage of unescaped output
  • Flows with unsanitized paths detected
  • Only 1 nonce check on 4 entry points
Vulnerabilities
1

Gravitate Automated Tester Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58645medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gravitate Automated Tester <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Gravitate Automated Tester Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
64
19 escaped
Nonce Checks
1
Capability Checks
2
File Operations
6
External Requests
6
Bundled Libraries
0

Output Escaping

23% escaped83 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
admin (gravitate-tester.php:498)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Gravitate Automated Tester Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_grav_run_testgravitate-tester.php:40
authwp_ajax_grav_get_test_reportgravitate-tester.php:41
noprivwp_ajax_grav_get_test_reportgravitate-tester.php:42
authwp_ajax_grav_run_fix_testgravitate-tester.php:43
WordPress Hooks 6
actionadmin_enqueue_scriptsgravitate-plugin-settings.php:12
actionadmin_menugravitate-tester.php:37
actioninitgravitate-tester.php:38
actionwp_headgravitate-tester.php:95
actionwp_footergravitate-tester.php:100
filtershow_admin_bargravitate-tester.php:105
Maintenance & Trust

Gravitate Automated Tester Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJun 24, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Gravitate Automated Tester Developer Profile

Gravitate

1 plugin · 30 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravitate Automated Tester

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravitate-automated-tester/
Version Parameters
gravitate-automated-tester/style.css?ver=gravitate-automated-tester/script.js?ver=

HTML / DOM Fingerprints

JS Globals
GRAV_TEST_AUTH_KEY
FAQ

Frequently Asked Questions about Gravitate Automated Tester