
Gravity Forms Business Hours by GravityView Security & Risk Analysis
wordpress.org/plugins/gravity-forms-business-hoursAdd a Business Hours field to Gravity Forms.
Is Gravity Forms Business Hours by GravityView Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms Business Hours by GravityView has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of gravity-forms-business-hours v2.1.3 reveals a generally strong security posture. The plugin has zero identified entry points that are unprotected, indicating that any interactive elements are likely behind appropriate authentication and authorization checks. The complete absence of dangerous functions, file operations, and external HTTP requests further reduces the attack surface. All SQL queries utilize prepared statements, which is a critical best practice for preventing SQL injection vulnerabilities. The plugin also exhibits good practices in terms of output escaping, with a high percentage of outputs being properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no known CVEs recorded, which suggests a history of secure development and diligent patching if issues have arisen in the past.
However, the analysis does flag some areas for consideration. The lack of any identified nonce checks or capability checks across the analyzed entry points is a significant concern. While the attack surface appears to be zero, if any functionality were to be discovered or added that requires user interaction, the absence of these fundamental security mechanisms could expose the plugin to CSRF attacks or unauthorized privilege escalation. The taint analysis showing zero flows is also notable; while seemingly positive, it could also indicate that the analysis was not able to identify any flows to analyze, or that the plugin's functionality is very limited. Given the otherwise robust findings, the lack of explicit security checks on potential interaction points is the primary area of weakness.
In conclusion, gravity-forms-business-hours v2.1.3 demonstrates strong foundational security practices, particularly regarding SQL and output sanitization, and has a commendable vulnerability-free history. The main area of concern is the apparent absence of nonce and capability checks, which are essential for a comprehensive security strategy, especially if the plugin evolves or has undiscovered interaction points. This is a weakness that, while not immediately exploitable based on the provided data, represents a missed opportunity for enhanced security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low output escaping coverage
Gravity Forms Business Hours by GravityView Security Vulnerabilities
Gravity Forms Business Hours by GravityView Code Analysis
Output Escaping
Gravity Forms Business Hours by GravityView Attack Surface
WordPress Hooks 3
Maintenance & Trust
Gravity Forms Business Hours by GravityView Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms Business Hours by GravityView Alternatives
Contact Form Migrator from Gravity Forms to Formidable
formidable-gravity-forms-importer
Migrate your WordPress contact forms automatically from Gravity Forms to Formidable Forms.
ABN Lookup for Gravity Forms
abn-lookup-for-gravity-forms
Integrate the Australian Business Register ABN Lookup tool in Gravity Forms
Gravity Forms Light Blue API Add-On
gravity-forms-light-blue-api-add-on
Send information directly from your Gravity Forms forms to your Light Blue account.
Folders4Gravity – Folders for Gravity Forms and GravityView
folders-4-gravity
Organize Gravity Forms and Views with flexible drag-and-drop folders. Reduce admin clutter, streamline workflows, and keep your workspace tidy.
Shift8 Integration for Gravity Forms and SAP Business One
shift8-integration-for-gravity-forms-and-sap-business-one
Integrates Gravity Forms with SAP Business One to automatically create Business Partner records from form submissions.
Gravity Forms Business Hours by GravityView Developer Profile
23 plugins · 14K total installs
How We Detect Gravity Forms Business Hours by GravityView
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-business-hours/includes/class-gf-field-business-hours.php/wp-content/plugins/gravity-forms-business-hours/includes/helper-functions.php/wp-content/plugins/gravity-forms-business-hours/includes/class-gf-business-hours.php