Gravity Forms Multi Currency Security & Risk Analysis

wordpress.org/plugins/gravity-forms-multi-currency

Per form currency for Gravity Forms.

400 active installs v1.7.1 PHP + WP 3.0.1+ Updated Apr 9, 2014
currencyformsgravitygravity-formgravity-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms Multi Currency Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms Multi Currency has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of 'gravity-forms-multi-currency' v1.7.1 reveals a seemingly secure plugin with no immediately apparent attack vectors in terms of entry points like AJAX handlers, REST API routes, or shortcodes. The absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries, suggests good development practices in these critical areas. However, a significant concern arises from the output escaping, where 100% of the analyzed outputs are not properly escaped. This lack of escaping poses a substantial risk for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is directly rendered in the output without sanitization.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator of the plugin's overall security maturity and the development team's responsiveness to security issues. However, the lack of any recorded vulnerabilities could also, in rare cases, indicate limited historical testing or a lack of exposure to sophisticated attack vectors. Given the presence of unescaped outputs, the absence of vulnerability history should not be a reason to dismiss potential security weaknesses. The overall security posture is a mixed bag, with strong foundations in some areas but a critical oversight in output sanitization that requires immediate attention.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Gravity Forms Multi Currency Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms Multi Currency Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Gravity Forms Multi Currency Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitgravity-forms-multi-currency.php:23
actionwpgravity-forms-multi-currency.php:37
filtergform_currencygravity-forms-multi-currency.php:38
actiongform_admin_pre_rendergravity-forms-multi-currency.php:41
filtergform_form_settingsgravity-forms-multi-currency.php:42
filtergform_pre_form_settings_savegravity-forms-multi-currency.php:43
actiongform_editor_jsgravity-forms-multi-currency.php:44
actiongform_entry_detail_content_beforegravity-forms-multi-currency.php:46
filtergform_pre_rendergravity-forms-multi-currency.php:49
Maintenance & Trust

Gravity Forms Multi Currency Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedApr 9, 2014
PHP min version
Downloads13K

Community Trust

Rating68/100
Number of ratings7
Active installs400
Developer Profile

Gravity Forms Multi Currency Developer Profile

ilanco

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Multi Currency

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-multi-currency/gravity-forms-multi-currency.php

HTML / DOM Fingerprints

JS Globals
form.currency
FAQ

Frequently Asked Questions about Gravity Forms Multi Currency