Gravity Forms Business Hours by GravityView Security & Risk Analysis

wordpress.org/plugins/gravity-forms-business-hours

Add a Business Hours field to Gravity Forms.

100 active installs v2.1.3 PHP + WP 3.3+ Updated Apr 23, 2019
businessgravitygravity-formgravity-formsgravityview
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms Business Hours by GravityView Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms Business Hours by GravityView has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of gravity-forms-business-hours v2.1.3 reveals a generally strong security posture. The plugin has zero identified entry points that are unprotected, indicating that any interactive elements are likely behind appropriate authentication and authorization checks. The complete absence of dangerous functions, file operations, and external HTTP requests further reduces the attack surface. All SQL queries utilize prepared statements, which is a critical best practice for preventing SQL injection vulnerabilities. The plugin also exhibits good practices in terms of output escaping, with a high percentage of outputs being properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no known CVEs recorded, which suggests a history of secure development and diligent patching if issues have arisen in the past.

However, the analysis does flag some areas for consideration. The lack of any identified nonce checks or capability checks across the analyzed entry points is a significant concern. While the attack surface appears to be zero, if any functionality were to be discovered or added that requires user interaction, the absence of these fundamental security mechanisms could expose the plugin to CSRF attacks or unauthorized privilege escalation. The taint analysis showing zero flows is also notable; while seemingly positive, it could also indicate that the analysis was not able to identify any flows to analyze, or that the plugin's functionality is very limited. Given the otherwise robust findings, the lack of explicit security checks on potential interaction points is the primary area of weakness.

In conclusion, gravity-forms-business-hours v2.1.3 demonstrates strong foundational security practices, particularly regarding SQL and output sanitization, and has a commendable vulnerability-free history. The main area of concern is the apparent absence of nonce and capability checks, which are essential for a comprehensive security strategy, especially if the plugin evolves or has undiscovered interaction points. This is a weakness that, while not immediately exploitable based on the provided data, represents a missed opportunity for enhanced security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping coverage
Vulnerabilities
None known

Gravity Forms Business Hours by GravityView Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms Business Hours by GravityView Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Attack Surface

Gravity Forms Business Hours by GravityView Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergravityforms_business_hours_output_templateclass-gf-field-business-hours.php:30
actiongform_editor_js_set_default_valuesclass-gf-field-business-hours.php:33
actiongform_loadedgravity-forms-business-hours.php:30
Maintenance & Trust

Gravity Forms Business Hours by GravityView Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 23, 2019
PHP min version
Downloads7K

Community Trust

Rating74/100
Number of ratings6
Active installs100
Developer Profile

Gravity Forms Business Hours by GravityView Developer Profile

Zack Katz

23 plugins · 14K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Business Hours by GravityView

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-business-hours/includes/class-gf-field-business-hours.php/wp-content/plugins/gravity-forms-business-hours/includes/helper-functions.php/wp-content/plugins/gravity-forms-business-hours/includes/class-gf-business-hours.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Gravity Forms Business Hours by GravityView