
Gravity Forms + Custom Post Types Security & Risk Analysis
wordpress.org/plugins/gravity-forms-custom-post-typesMap your Gravity-Forms-generated posts to a custom post type and/or custom taxonomies.
Is Gravity Forms + Custom Post Types Safe to Use in 2026?
Generally Safe
Score 100/100Gravity Forms + Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gravity-forms-custom-post-types" v3.1.30 plugin presents a seemingly strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate no dangerous functions, no direct SQL queries (all using prepared statements), no file operations, and no external HTTP requests. The lack of reported CVEs and past vulnerabilities reinforces this impression of a secure plugin.
However, a significant concern arises from the output escaping analysis. With 9 total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not properly sanitized before being displayed to users could be exploited. The absence of nonce checks and capability checks on the identified entry points (though there are none) is noted, but the primary and most immediate risk stems from the unescaped output, which could be a significant security weakness despite the other positive indicators.
In conclusion, while the plugin demonstrates good practices by avoiding dangerous functions and utilizing prepared statements for its (non-existent) SQL queries, the complete lack of output escaping is a critical oversight. This single weakness could expose the plugin and the WordPress site to severe XSS attacks. The vulnerability history shows no prior issues, which is positive, but it does not mitigate the current risk identified in the static analysis.
Key Concerns
- Output escaping issues
Gravity Forms + Custom Post Types Security Vulnerabilities
Gravity Forms + Custom Post Types Release Timeline
Gravity Forms + Custom Post Types Code Analysis
Output Escaping
Gravity Forms + Custom Post Types Attack Surface
WordPress Hooks 21
Maintenance & Trust
Gravity Forms + Custom Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms + Custom Post Types Alternatives
PTAPS – Post Type Archive Pages and Permalink Settings
post-type-archive-pages-and-permalink-settings
Use archive pages for custom post types and improve WordPress SEO by managing permalinks for custom post types and taxonomies.
Elite Stay Helper – Create Cpts and taxonomy for rooms
elite-stay-helper
The plugin by Kamaldhari Infotech streamlines hotel management, offering custom post types, taxonomy, and meta fields. Easily handle rooms,testimonial …
Winecoza
winecoza
A plugin that creates a custom post type for Winecoza and a taxonomy, and uses a different template for posts with a specific taxonomy type.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Essential Content Types
essential-content-types
Essential Content Types allows you to feature the impressive content through different content/post types on your website just the way you want it.
Gravity Forms + Custom Post Types Developer Profile
1 plugin · 10K total installs
How We Detect Gravity Forms + Custom Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-custom-post-types/css/gfcptaddon.css/wp-content/plugins/gravity-forms-custom-post-types/js/gfcptaddon.js/wp-content/plugins/gravity-forms-custom-post-types/js/select2.min.js/wp-content/plugins/gravity-forms-custom-post-types/js/gfcptaddon.js/wp-content/plugins/gravity-forms-custom-post-types/js/select2.min.jsgravity-forms-custom-post-types/css/gfcptaddon.css?ver=gravity-forms-custom-post-types/js/gfcptaddon.js?ver=gravity-forms-custom-post-types/js/select2.min.js?ver=HTML / DOM Fingerprints
gfcpt-select-enhancedgfcpt-tag-enhanceddata-save-taxonomydata-save-post-typedata-placeholderwindow.gfcpt_tag_inputswindow.gfcpt_tag_taxonomies