
Gravity Forms: Force SSL Security & Risk Analysis
wordpress.org/plugins/gravity-forms-force-sslAn addon to Gravity Forms to add an option to force your forms to be loaded SSL only.
Is Gravity Forms: Force SSL Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms: Force SSL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `gravity-forms-force-ssl` v1.4.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, dangerous functions, or direct SQL queries is highly commendable. Furthermore, the complete lack of unsanitized output and the presence of a nonce check indicate good development practices for securing plugin operations. The plugin's history is also clean, with no known CVEs, which suggests a well-maintained and secure codebase over time.
However, the presence of a single flow with an unsanitized path, even if not critical or high severity in the taint analysis, warrants attention. While the overall attack surface is zero, this single unsanitized path represents a potential blind spot. The complete absence of capability checks is also a minor concern, as it implies that all actions, if any were to be discovered through further analysis, are not explicitly restricted by user roles. Despite these minor points, the plugin's design and historical lack of vulnerabilities make it appear relatively secure.
Key Concerns
- Flow with unsanitized path
- No capability checks
Gravity Forms: Force SSL Security Vulnerabilities
Gravity Forms: Force SSL Code Analysis
Data Flow Analysis
Gravity Forms: Force SSL Attack Surface
WordPress Hooks 7
Maintenance & Trust
Gravity Forms: Force SSL Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms: Force SSL Alternatives
Admin SSL
admin-ssl-secure-admin
Admin SSL secures login page, admin area, posts, pages - whatever you want - using Private SSL.
Global Payments SecureSubmit Addon for Gravity Forms
heartland-secure-submit-addon-for-gravity-forms
SecureSubmit allows merchants to take PCI-Friendly Credit Card payments with Gravity Forms using Global Payments Payment Gateway.
SSL for Logged In Users
ssl-for-logged-in-users
Forces all logged in users to stay on SSL connection
PII Tokenizer
pii-tokenizer
Secure Personally Identifiable Information (PII) with vaultless tokenization. Easily tokenize and detokenize profile and address fields in your forms …
BBQ Firewall – Fast & Powerful Firewall Security
block-bad-queries
The fastest firewall plugin for WordPress. Protect against a wide range of threats with minimal performance impact.
Gravity Forms: Force SSL Developer Profile
5 plugins · 770 total installs
How We Detect Gravity Forms: Force SSL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-force-ssl/form-settings.php/wp-content/plugins/gravity-forms-force-ssl/plugin-settings.phpHTML / DOM Fingerprints
force_ssl