
Paystation (3 Party Hosted) for Gravity forms Security & Risk Analysis
wordpress.org/plugins/gravity-forms-paystation-3-party-hostedIntegrates Gravity Forms with the Paystation 3 party hosted payment gateway allowing end-users to purchase goods and services via Gravity Forms.
Is Paystation (3 Party Hosted) for Gravity forms Safe to Use in 2026?
Generally Safe
Score 92/100Paystation (3 Party Hosted) for Gravity forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gravity-forms-paystation-3-party-hosted" plugin v1.5.6 presents a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, executing all SQL queries using prepared statements, and implementing nonce and capability checks for its identified entry points. There are no recorded vulnerabilities or CVEs, suggesting a history of relative security.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks, creating a substantial attack surface for unauthorized actions. While the taint analysis did not identify critical or high severity issues, it did reveal two flows with unsanitized paths, which could potentially be exploited if the AJAX handlers are not properly secured. The low percentage of properly escaped output (10%) is also a concern, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, the plugin has a strong foundation in terms of SQL security and the absence of known vulnerabilities. Nevertheless, the unprotected AJAX endpoints and the prevalence of unescaped output represent notable security weaknesses that could be leveraged by attackers. Addressing these specific issues should be a priority to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Low percentage of properly escaped output
Paystation (3 Party Hosted) for Gravity forms Security Vulnerabilities
Paystation (3 Party Hosted) for Gravity forms Release Timeline
Paystation (3 Party Hosted) for Gravity forms Code Analysis
Output Escaping
Data Flow Analysis
Paystation (3 Party Hosted) for Gravity forms Attack Surface
AJAX Handlers 2
WordPress Hooks 23
Maintenance & Trust
Paystation (3 Party Hosted) for Gravity forms Maintenance & Trust
Maintenance Signals
Community Trust
Paystation (3 Party Hosted) for Gravity forms Alternatives
Click & Pledge for Gravity Forms
gravity-forms-click-pledge
Add a credit card payment gateway for Click & Pledge to the Gravity Forms plugin
Gravity Forms Eway
gravityforms-eway
Easily create online payment forms with Gravity Forms and Eway.
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Opayo Form Payment Gateway for Gravity Forms
sagepay-form-payment-gateway-for-gravity-forms
Accept card payments in Gravity Forms using Opayo Form (hosted checkout by Elavon)—customers pay on Opayo’s pages, not on your server.
ZaakPay
zaakpay
Seamlessly integrate Zaakpay payment gateway with WooCommerce for secure and reliable online payments.
Paystation (3 Party Hosted) for Gravity forms Developer Profile
2 plugins · 130 total installs
How We Detect Paystation (3 Party Hosted) for Gravity forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-paystation-3-party-hosted/style-admin.cssgravity-forms-paystation-3-party-hosted/style-admin.css?ver=gravityforms-paystation.php?ver=HTML / DOM Fingerprints
data-gfpaystation-form-idgfpaystation_form_idgfpaystation_form_fields/wp-json/gfpaystation/v1/form/