
Gravity Forms: Notification Attachments Security & Risk Analysis
wordpress.org/plugins/gravity-forms-notification-attachmentsA WordPress addon for Gravity Forms to add attachments to notification emails.
Is Gravity Forms: Notification Attachments Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms: Notification Attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gravity-forms-notification-attachments" plugin version 1.5 exhibits a mixed security posture. On the positive side, the code analysis reveals no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests. This indicates a generally well-written and secure foundation for these specific areas. The absence of known CVEs and a clean vulnerability history further contribute to a perception of reliability and diligence in past development.
However, significant concerns arise from the attack surface and code signals. The presence of one unprotected AJAX handler is a major security weakness. This entry point could be exploited by unauthenticated users to trigger potentially sensitive actions within the plugin. Furthermore, the taint analysis shows one flow with unsanitized paths, which, while not categorized as critical or high severity in this report, still represents a potential vector for unexpected behavior or information disclosure if it interacts with user-supplied data. The low percentage of properly escaped output (25%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, as dynamic content may not be adequately neutralized before being rendered to users.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and avoiding external dependencies, the unprotected AJAX endpoint and the potential for XSS due to insufficient output escaping are critical areas that need immediate attention. The clean vulnerability history is a strength, but it does not negate the inherent risks identified in the static analysis of this specific version. Addressing the unprotected AJAX handler and improving output escaping are paramount to strengthening the plugin's security.
Key Concerns
- Unprotected AJAX handler
- Low output escaping percentage
- Flow with unsanitized paths
- No nonce checks on AJAX
- No capability checks on AJAX
Gravity Forms: Notification Attachments Security Vulnerabilities
Gravity Forms: Notification Attachments Code Analysis
Output Escaping
Data Flow Analysis
Gravity Forms: Notification Attachments Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Gravity Forms: Notification Attachments Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms: Notification Attachments Alternatives
Mass Email Notifications for Gravity Forms
mass-email-notifications-for-gravity-forms
Mass Email Notifications for Gravity Forms allows you to send your notifications to anyone who filled out one of your forms!
Notification Attachments for Gravity Forms
notification-attachments-for-gravity-forms
Send attachment in Gravity Forms Notification
Ultimate WP Mail
ultimate-wp-mail
Custom email and SMS notifications. Automatic send actions. WPForms SMS integration. WooCommerce notifications for purchases, abandoned cart and more!
Drip for Gravity Forms
drip-gravity-forms
Integrates Gravity Forms with personalized Email Marketing tool Drip.
Gravity Forms To Excel AddOn
gravity-forms-to-excel-addon
Gravity Forms AddOn which saves form data into a given Excel document and attaches it to notification emails
Gravity Forms: Notification Attachments Developer Profile
5 plugins · 770 total installs
How We Detect Gravity Forms: Notification Attachments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-notification-attachments/script.js/wp-content/plugins/gravity-forms-notification-attachments/script.min.js/wp-content/plugins/gravity-forms-notification-attachments/style.cssgravity-forms-notification-attachments/script.js?ver=gravity-forms-notification-attachments/script.min.js?ver=gravity-forms-notification-attachments/style.css?ver=HTML / DOM Fingerprints
gform_notification_attachmentremoveflfile-detailstitlemime<!-- / notification attachment -->data-idclass="remove dashicons dashicons-dismiss"src="class="fl"class="fl file-details"class="title"+5 more