Gravity Forms IBAN Security & Risk Analysis

wordpress.org/plugins/gravity-forms-iban

Add an IBAN input mask and IBAN validation to your Gravity Form.

600 active installs v1.0 PHP + WP 3.8+ Updated Jun 3, 2015
ibansepa
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms IBAN Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms IBAN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'gravity-forms-iban' v1.0 plugin exhibits a strong security posture. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unescaped output is highly commendable. Furthermore, the lack of any recorded vulnerabilities, including critical or high-severity ones, suggests a well-developed and tested codebase. The plugin also demonstrates good security practices by not exposing any direct entry points through AJAX, REST API, or shortcodes without proper authentication checks, and it has a minimal attack surface.

However, a notable absence of nonce checks and capability checks across all entry points, though there are currently no exposed entry points, presents a potential future risk. Should any new entry points be introduced or existing ones modified without implementing these crucial security measures, the plugin could become vulnerable to various attacks, such as Cross-Site Request Forgery (CSRF) or unauthorized actions. The plugin's complete lack of external HTTP requests and file operations is also a positive security indicator, reducing the potential for code injection or data leakage.

In conclusion, 'gravity-forms-iban' v1.0 appears secure at present, largely due to its limited functionality and attack surface. Its clean code signals and absence of past vulnerabilities are strong positives. The primary area for potential improvement lies in proactively implementing nonce and capability checks, especially if the plugin's functionality or entry points are expected to expand in the future, to maintain this high level of security.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Gravity Forms IBAN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms IBAN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Gravity Forms IBAN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergform_input_masksgform-iban.php:25
filtergform_input_mask_scriptgform-iban.php:45
filtergform_validationgform-iban.php:74
Maintenance & Trust

Gravity Forms IBAN Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 3, 2015
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings5
Active installs600
Developer Profile

Gravity Forms IBAN Developer Profile

Jeroen Schmit

5 plugins · 1K total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
65 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms IBAN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
jQuery('#input_{form_id}_{field_id}').mask('aa99 ?**** **** **** **** **** **** **** ****');
FAQ

Frequently Asked Questions about Gravity Forms IBAN