
Gravity Forms PDF Security & Risk Analysis
wordpress.org/plugins/gravity-forms-pdfA basic plugin that allows Gravity Forms Entries to be Viewed and Download in a Printer Friendly PDF Layout
Is Gravity Forms PDF Safe to Use in 2026?
Generally Safe
Score 100/100Gravity Forms PDF has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gravity-forms-pdf" plugin v0.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and having a clean vulnerability history with no recorded CVEs. The absence of a significant attack surface through AJAX handlers, REST API routes, shortcodes, and cron events is also a strength. However, several concerning signals emerge from the static analysis.
The presence of the "create_function" dangerous function, while not directly tied to a taint flow in this analysis, represents a potential for insecure code execution if used with unsanitized input. More critically, the taint analysis revealed 4 flows with unsanitized paths, one of which is rated as High severity. This indicates a potential for data to be manipulated or exploited due to improper sanitization. Furthermore, only 23% of output is properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks if user-controlled data is echoed directly. The complete lack of nonce checks and capability checks on any entry points is a significant oversight, as these are fundamental security mechanisms for preventing unauthorized actions and ensuring proper authentication/authorization.
In conclusion, while the plugin has a clean history and employs secure SQL practices, the identified taint flows, poor output escaping, and absence of critical security checks like nonces and capability checks present notable risks. The use of the "create_function" also warrants attention. Addressing these issues would significantly improve the plugin's overall security. The bundled libraries, dompdf and TCPDF, could also represent a risk if they are outdated or have known vulnerabilities, though this is not directly indicated in the provided data.
Key Concerns
- High severity taint flow with unsanitized path
- Low output escaping percentage (23%)
- No nonce checks
- No capability checks
- Dangerous function 'create_function' used
- 4 flows with unsanitized paths
Gravity Forms PDF Security Vulnerabilities
Gravity Forms PDF Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Gravity Forms PDF Attack Surface
WordPress Hooks 3
Maintenance & Trust
Gravity Forms PDF Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms PDF Alternatives
PDF Zip Downloader for Gravity Forms
pdf-zip-downloader-for-gravity-forms
Generates a ZIP file that includes a PDF and the attachments from a Gravity Forms entry.
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
GravityExport Lite for Gravity Forms
gf-entries-in-excel
Export all Gravity Forms entries to Excel (.xlsx) or CSV via a download button or a secret shareable URL.
PDF Catalog for WooCommerce
pdf-catalog-woocommerce
Generate dynamic PDF catalogs for WooCommerce products. Allow customers to download shop, category, or single product catalogs including images, price …
PDF Generator for WordPress Elementor
pdf-generator-addon-for-elementor-page-builder
The ultimate WordPress PDF generator for Elementor. Easily export to PDF, add a download button, and convert WooCommerce products to PDF.
Gravity Forms PDF Developer Profile
2 plugins · 130 total installs
How We Detect Gravity Forms PDF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
buttonjQuery