Gravity Forms Janrain Add-on Security & Risk Analysis

wordpress.org/plugins/gravity-forms-janrain-add-on

Integrate Gravity Forms with Janrain Engage social login to pre-fill forms.

10 active installs v0.3 PHP + WP 3.4+ Updated Aug 19, 2013
form-prefillformssocial-login
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gravity Forms Janrain Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms Janrain Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The Gravity Forms Janrain Add-on v0.3 exhibits a concerning security posture primarily due to its unprotected entry points and unsanitized data flows. While the plugin demonstrates good practices by exclusively using prepared statements for SQL and avoiding dangerous functions, these strengths are overshadowed by critical vulnerabilities identified in the taint analysis. The presence of two 'flows with unsanitized paths' classified as 'High severity' in the taint analysis directly points to potential security risks where user-supplied data could be improperly handled, leading to unintended consequences or even exploitation. Furthermore, the plugin exposes two AJAX handlers without any authentication checks, creating a significant attack surface that could be leveraged by unauthenticated users. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a lack of past exploits or perhaps limited adoption and auditing. However, this historical data should not alleviate concerns about the present static analysis findings, which highlight immediate and actionable risks.

Key Concerns

  • AJAX handlers without auth checks
  • High severity taint flows (2)
  • Unsanitized paths in taint analysis (2)
  • Missing capability checks
  • Outputs not properly escaped (33%)
Vulnerabilities
None known

Gravity Forms Janrain Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Gravity Forms Janrain Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

67% escaped15 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
janrain_gforms_retrieve_userdata (ajax-response.php:23)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Gravity Forms Janrain Add-on Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_return-tokenajax-response.php:55
noprivwp_ajax_return-tokenajax-response.php:56
WordPress Hooks 7
actionadmin_enqueue_scriptsadmin-settings.php:34
actiongform_field_standard_settingsadmin-settings.php:67
filtergform_tooltipsadmin-settings.php:82
actiongform_editor_jsadmin-settings.php:137
filtergform_addon_navigationadmin-settings.php:157
actiongform_add_field_buttonsadmin-settings.php:312
filtergform_field_contentgravity-forms-janrain-add-on.php:82
Maintenance & Trust

Gravity Forms Janrain Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedAug 19, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Gravity Forms Janrain Add-on Developer Profile

goldenapples

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Janrain Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-janrain-add-on/settings.js
Script Paths
https://rpxnow.com/js/lib/janrain/engage.jshttp://widget-cdn.rpxnow.com/js/lib/janrain/engage.js

HTML / DOM Fingerprints

CSS Classes
janrain-provider-icon-32janrain-provider-icon-gfield_admin_iconsgfield_admin_header_titlefield_delete_iconedit_icon_collapsedjanrainEngageEmbed
HTML Comments
Copyright 2012-2013 Janrain, Inc.This program is free software: you can redistribute it and/or modifyunder the terms of the GNU General Public License as published bythe Free Software Foundation, either version 3 of the License, or+21 more
Data Attributes
socialPrefillsocialPrefillWithjanrain_engage_prefillsocial_prefill
JS Globals
janrainJANRAIN_GFORMS_DIRECTORYengage-integration-settings
FAQ

Frequently Asked Questions about Gravity Forms Janrain Add-on