iContact for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gravity-forms-icontactIntegrate the remarkable Gravity Forms plugin with iContact.
Is iContact for Gravity Forms Safe to Use in 2026?
Use With Caution
Score 63/100iContact for Gravity Forms has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The gravity-forms-icontact plugin v1.3.2 exhibits a mixed security posture. On the positive side, it has a small attack surface with no unprotected entry points and a good percentage of SQL queries utilizing prepared statements. It also incorporates nonce and capability checks, indicating some awareness of secure coding practices. However, a significant concern lies in the output escaping, with only 36% of outputs being properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks.
The vulnerability history reveals a concerning pattern. The plugin has a known medium severity CVE that remains unpatched. The common vulnerability type being Cross-site Scripting, coupled with the low percentage of properly escaped outputs identified in the static analysis, strongly suggests that the previous vulnerability was likely related to improper output sanitization. The identified taint flow with an unsanitized path further amplifies this concern, as it indicates a potential avenue for malicious input to be processed without adequate cleaning.
In conclusion, while the plugin has some good security fundamentals in place, the prevalence of unescaped output and the existence of an unpatched XSS vulnerability necessitate caution. The identified taint flow also highlights a specific area of potential weakness. Users should be aware of the risk of XSS, especially when considering the past vulnerability and the current static analysis findings. Addressing the output escaping and patching the known vulnerability are critical steps to improving the plugin's security.
Key Concerns
- Unpatched CVE (medium severity)
- Low percentage of properly escaped outputs (36%)
- Flow with unsanitized path identified
iContact for Gravity Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
iContact for Gravity Forms <= 1.3.2 - Reflected Cross-Site Scripting
iContact for Gravity Forms Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
iContact for Gravity Forms Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
iContact for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
iContact for Gravity Forms Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
iContact for Gravity Forms Developer Profile
23 plugins · 14K total installs
How We Detect iContact for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-icontact/css/gf_icontact_admin.css/wp-content/plugins/gravity-forms-icontact/js/gf_icontact_admin.js/wp-content/plugins/gravity-forms-icontact/images/icontact_wordpress_icon_32.png/wp-content/plugins/gravity-forms-icontact/js/gf_icontact_admin.jsgravity-forms-icontact/css/gf_icontact_admin.css?ver=gravity-forms-icontact/js/gf_icontact_admin.js?ver=HTML / DOM Fingerprints
gfi_icontact_setting_section<!-- iContact Settings --><!-- iContact Feed -->data-feed_idgf_icontact_admin