
GF Windcave Free Security & Risk Analysis
wordpress.org/plugins/gravity-forms-dps-pxpayEasily create online payment forms with Gravity Forms and Windcave (DPS Payment Express) PxPay
Is GF Windcave Free Safe to Use in 2026?
Generally Safe
Score 100/100GF Windcave Free has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "gravity-forms-dps-pxpay" plugin v2.6.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and properly escaping a high percentage of its output. The absence of critical or high-severity taint flows and the fact that all known CVEs are patched are also strong indicators of a relatively well-maintained codebase concerning past vulnerabilities.
However, a significant concern arises from the static analysis, which reveals a single entry point in the form of an AJAX handler that lacks authentication checks. This unprotected endpoint represents a direct attack vector that could be exploited if it handles user-supplied data without proper validation or authorization. While the plugin has a history of a single medium-severity cross-site scripting vulnerability from 2015, the presence of an unprotected AJAX handler in the current version poses a more immediate and potentially exploitable risk.
In conclusion, while the plugin has a good track record regarding patched vulnerabilities and secure coding practices for SQL and output, the unprotected AJAX handler is a critical flaw that significantly diminishes its overall security. The absence of a taint flow analysis for the identified entry point makes it difficult to assess the exact impact, but the presence of an unauthenticated endpoint is inherently risky.
Key Concerns
- Unprotected AJAX handler present
- One file operation
- One external HTTP request
GF Windcave Free Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GF Windcave Free <= 1.4.3 - Reflected Cross-Site Scripting
GF Windcave Free Release Timeline
GF Windcave Free Code Analysis
SQL Query Safety
Output Escaping
GF Windcave Free Attack Surface
AJAX Handlers 1
WordPress Hooks 21
Maintenance & Trust
GF Windcave Free Maintenance & Trust
Maintenance Signals
Community Trust
GF Windcave Free Alternatives
Gravity Forms Eway
gravityforms-eway
Easily create online payment forms with Gravity Forms and Eway.
Opayo Form Payment Gateway for Gravity Forms
sagepay-form-payment-gateway-for-gravity-forms
Accept card payments in Gravity Forms using Opayo Form (hosted checkout by Elavon)—customers pay on Opayo’s pages, not on your server.
Click & Pledge for Gravity Forms
gravity-forms-click-pledge
Add a credit card payment gateway for Click & Pledge to the Gravity Forms plugin
Paystation (3 Party Hosted) for Gravity forms
gravity-forms-paystation-3-party-hosted
Integrates Gravity Forms with the Paystation 3 party hosted payment gateway allowing end-users to purchase goods and services via Gravity Forms.
Docket Connector
docket-connector
Create invoices within your Docket account from Gravity Forms.
GF Windcave Free Developer Profile
13 plugins · 153K total installs
How We Detect GF Windcave Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-dps-pxpay/static/css/admin-update-v1.css/wp-content/plugins/gravity-forms-dps-pxpay/static/js/admin-update-v1.js/wp-content/plugins/gravity-forms-dps-pxpay/static/js/admin-update-v1.jsgravity-forms-dps-pxpay/static/js/admin-update-v1.js?ver=gravity-forms-dps-pxpay/static/css/admin-update-v1.css?ver=HTML / DOM Fingerprints
gfdpspxpay_updatev1