
Gravity Forms ExactTarget Add-on Security & Risk Analysis
wordpress.org/plugins/gravity-forms-exacttarget> This plugin requires the amazing Gravity Forms plugin. Don't use Gravity Forms? Get the plugin, then start using this great plugin!
Is Gravity Forms ExactTarget Add-on Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms ExactTarget Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Gravity Forms ExactTarget plugin v1.0.6 presents a generally good security posture based on the static analysis. The absence of any known CVEs and the plugin's overall history of zero vulnerabilities suggest a commitment to security by its developers. The limited attack surface, with only two AJAX handlers and no REST API routes, shortcodes, or cron events, is a positive indicator. Furthermore, all identified entry points have authentication checks, and there are no unpatched vulnerabilities, which significantly reduces the risk of known exploits. The use of prepared statements for the majority of SQL queries and the presence of nonce and capability checks are also good security practices. However, there are areas of concern. The output escaping is only properly handled in 39% of cases, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. Additionally, the taint analysis revealed one flow with an unsanitized path, which could lead to insecure file operations or path traversal if exploited. The plugin also makes two external HTTP requests, which, while not inherently insecure, should be carefully scrutinized for potential vulnerabilities in the external services it communicates with.
Key Concerns
- Low percentage of properly escaped output
- Taint flow with unsanitized path
Gravity Forms ExactTarget Add-on Security Vulnerabilities
Gravity Forms ExactTarget Add-on Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Gravity Forms ExactTarget Add-on Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Gravity Forms ExactTarget Add-on Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms ExactTarget Add-on Alternatives
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
WP Gravity Forms Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
Contact Form 7 Gravity Forms Importer
contact-form-7-gravity-forms
Convert Contact Form 7 forms into Gravity Forms forms.
WP Gravity Forms Dynamics CRM
gf-dynamics-crm
Gravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
Gravity Forms Keap Feed
systasis-gf-infusionsoft-feed
Sync form submissions between Gravity Forms and Keap
Gravity Forms ExactTarget Add-on Developer Profile
23 plugins · 14K total installs
How We Detect Gravity Forms ExactTarget Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-exacttarget/css/exacttarget_admin.css/wp-content/plugins/gravity-forms-exacttarget/js/exacttarget_admin.js/wp-content/plugins/gravity-forms-exacttarget/js/exacttarget_admin.jsHTML / DOM Fingerprints
gfield_exacttarget_mapping