Gravity Forms ExactTarget Add-on Security & Risk Analysis

wordpress.org/plugins/gravity-forms-exacttarget

> This plugin requires the amazing Gravity Forms plugin. Don't use Gravity Forms? Get the plugin, then start using this great plugin!

20 active installs v1.0.6 PHP + WP 2.8+ Updated Jun 18, 2014
crmformformsgravitygravity-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms ExactTarget Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms ExactTarget Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The Gravity Forms ExactTarget plugin v1.0.6 presents a generally good security posture based on the static analysis. The absence of any known CVEs and the plugin's overall history of zero vulnerabilities suggest a commitment to security by its developers. The limited attack surface, with only two AJAX handlers and no REST API routes, shortcodes, or cron events, is a positive indicator. Furthermore, all identified entry points have authentication checks, and there are no unpatched vulnerabilities, which significantly reduces the risk of known exploits. The use of prepared statements for the majority of SQL queries and the presence of nonce and capability checks are also good security practices. However, there are areas of concern. The output escaping is only properly handled in 39% of cases, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. Additionally, the taint analysis revealed one flow with an unsanitized path, which could lead to insecure file operations or path traversal if exploited. The plugin also makes two external HTTP requests, which, while not inherently insecure, should be carefully scrutinized for potential vulnerabilities in the external services it communicates with.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flow with unsanitized path
Vulnerabilities
None known

Gravity Forms ExactTarget Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms ExactTarget Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
45
29 escaped
Nonce Checks
7
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

39% escaped74 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
edit_page (exacttarget.php:544)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gravity Forms ExactTarget Add-on Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_rg_update_feed_activeexacttarget.php:98
authwp_ajax_gf_select_exacttarget_formexacttarget.php:99
WordPress Hooks 7
actioninitexacttarget.php:28
filterplugin_action_linksexacttarget.php:48
filtertransient_update_pluginsexacttarget.php:60
filtermembers_get_capabilitiesexacttarget.php:71
filtergform_addon_navigationexacttarget.php:74
filtergform_tooltipsexacttarget.php:87
actiongform_post_submissionexacttarget.php:104
Maintenance & Trust

Gravity Forms ExactTarget Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 18, 2014
PHP min version
Downloads7K

Community Trust

Rating90/100
Number of ratings2
Active installs20
Developer Profile

Gravity Forms ExactTarget Add-on Developer Profile

Zack Katz

23 plugins · 14K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms ExactTarget Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-exacttarget/css/exacttarget_admin.css/wp-content/plugins/gravity-forms-exacttarget/js/exacttarget_admin.js
Script Paths
/wp-content/plugins/gravity-forms-exacttarget/js/exacttarget_admin.js

HTML / DOM Fingerprints

CSS Classes
gfield_exacttarget_mapping
FAQ

Frequently Asked Questions about Gravity Forms ExactTarget Add-on