Gravity Forms Auto Placeholders Security & Risk Analysis

wordpress.org/plugins/gravity-forms-auto-placeholders

Automatically converts all Gravity Form labels into HTML5 placeholders. Includes Modernizr to add placeholder support to Internet Explorer.

700 active installs v1.2 PHP + WP + Updated Oct 22, 2014
formsgravitygravity-formsplaceholderplaceholders
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms Auto Placeholders Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms Auto Placeholders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "gravity-forms-auto-placeholders" v1.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the plugin's attack surface. Furthermore, the code signals indicate good development practices, with all SQL queries utilizing prepared statements and all output being properly escaped. The presence of a capability check is also a positive indicator of security awareness.

Taint analysis revealing zero unsanitized flows, including no critical or high severity issues, further reinforces the plugin's apparent security. The vulnerability history showing zero known CVEs, both patched and unpatched, and no recorded common vulnerability types, suggests a history of secure development or proactive vulnerability management.

In conclusion, based on this data, the plugin appears to be highly secure. The lack of identified vulnerabilities, robust code signals, and a minimal attack surface are significant strengths. There are no apparent weaknesses directly indicated by the provided analysis, suggesting a reliable and secure implementation.

Vulnerabilities
None known

Gravity Forms Auto Placeholders Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms Auto Placeholders Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Gravity Forms Auto Placeholders Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initgravity-forms-auto-placeholders.php:35
actionadmin_menugravity-forms-auto-placeholders.php:63
actionwp_enqueue_scriptsgravity-forms-auto-placeholders.php:93
Maintenance & Trust

Gravity Forms Auto Placeholders Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 22, 2014
PHP min version
Downloads16K

Community Trust

Rating60/100
Number of ratings5
Active installs700
Developer Profile

Gravity Forms Auto Placeholders Developer Profile

Josh Davis

5 plugins · 860 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Auto Placeholders

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-auto-placeholders/modernizr.placeholder.min.js/wp-content/plugins/gravity-forms-auto-placeholders/scripts.js
Script Paths
modernizr.placeholder.min.jsscripts.js
Version Parameters
gravity-forms-auto-placeholders/modernizr.placeholder.min.js?ver=gravity-forms-auto-placeholders/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
gfap_placeholder
JS Globals
gravityformsautoplaceholders
FAQ

Frequently Asked Questions about Gravity Forms Auto Placeholders