
Gravity Forms Data Persistence Add-On Reloaded Security & Risk Analysis
wordpress.org/plugins/gravity-forms-data-persistence-add-on-reloadedThis plugin makes your Gravity Forms data-persistent.
Is Gravity Forms Data Persistence Add-On Reloaded Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms Data Persistence Add-On Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "gravity-forms-data-persistence-add-on-reloaded" v3.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities. This suggests a developer who is mindful of common web application security pitfalls.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, and critically, neither of them includes authentication checks. This creates a substantial attack surface where unauthenticated users could potentially trigger these handlers, leading to unintended actions or information disclosure. Furthermore, only 50% of its output is properly escaped, which could open the door to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in the unescaped outputs.
The absence of any recorded vulnerabilities, while a positive sign, might also be attributed to the lack of known exploits targeting these specific weaknesses or the plugin's limited adoption. The lack of taint analysis flows is also noteworthy, meaning the analysis couldn't identify any data flow issues, which is good, but it's limited by the analysis itself. Overall, while the plugin avoids some common pitfalls, the unprotected AJAX endpoints and potential for XSS due to incomplete output escaping represent real security risks that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Incomplete output escaping (50%)
- No nonce checks on entry points
- No capability checks on entry points
Gravity Forms Data Persistence Add-On Reloaded Security Vulnerabilities
Gravity Forms Data Persistence Add-On Reloaded Code Analysis
Output Escaping
Gravity Forms Data Persistence Add-On Reloaded Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
Gravity Forms Data Persistence Add-On Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms Data Persistence Add-On Reloaded Alternatives
Gravity Forms Data Persistence Add-On
gravity-forms-data-persistence-add-on
This plugin makes your Gravity Forms data-persistent.
Gravity Forms Sticky Form
gravity-forms-sticky-form
A plugin that makes your Gravity Forms stick!
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Smart phone field for Gravity Forms
smart-phone-field-for-gravity-forms
A simple and nice plugin to get auto country flag from user ip address on gravity form phone field.
Gravity Slider Fields
gravity-slider-fields
Adds slider fields to Gravity Forms
Gravity Forms Data Persistence Add-On Reloaded Developer Profile
3 plugins · 880 total installs
How We Detect Gravity Forms Data Persistence Add-On Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-data-persistence-add-on-reloaded/gfdp.jsgravity-forms-data-persistence-add-on-reloaded/gfdp.js?ver=HTML / DOM Fingerprints
gfdp<!-- Gravity Forms Data Persistence Add-On Reloaded Version 3.3.1 -->gfdp_eventsgfdp_ajax