
Gravity Forms Periodic Notification E-Mails Security & Risk Analysis
wordpress.org/plugins/gravity-forms-periodic-notification-e-mails-by-weptileSends periodic e-mails for Gravity Forms entries created within the period. Daily, weekly, monthly updates instead of 1 e-mail per form entry.
Is Gravity Forms Periodic Notification E-Mails Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms Periodic Notification E-Mails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "gravity-forms-periodic-notification-e-mails-by-weptile" v1.2.2 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and includes a nonce check. There is no recorded vulnerability history, suggesting a generally stable codebase. However, the static analysis reveals significant concerns that cannot be ignored.
The presence of the `unserialize` function, while not explicitly shown to be exploitable in the taint analysis (which found no unsanitized paths), is a well-known risk vector. If user-supplied data is ever passed to `unserialize` without strict validation, it can lead to object injection vulnerabilities. Furthermore, only 27% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface appears small with no direct entry points like AJAX, REST API, or shortcodes, the cron event and the identified code signals pose potential threats.
In conclusion, while the lack of historical vulnerabilities and the use of prepared statements are strengths, the identified use of `unserialize` and the low percentage of proper output escaping create substantial security weaknesses. These areas require immediate attention to mitigate potential risks.
Key Concerns
- Unescaped output is a high risk for XSS
- Dangerous function 'unserialize' found
Gravity Forms Periodic Notification E-Mails Security Vulnerabilities
Gravity Forms Periodic Notification E-Mails Release Timeline
Gravity Forms Periodic Notification E-Mails Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Gravity Forms Periodic Notification E-Mails Attack Surface
WordPress Hooks 3
Scheduled Events 1
Maintenance & Trust
Gravity Forms Periodic Notification E-Mails Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms Periodic Notification E-Mails Alternatives
DayOfWeek
day-of-week
This plugin provides an easy, lightweight way to show content based on the day of the week.
Archivist
archivist
Gives you a few extra function for the archives widget including limiting the amount of archives to show and wether you want to display yearly, monthl …
Spice Archive Page
spice-archive-page
Plugin allows you to display yearly, monthly and daily archives in pages.
Weekly Fortune Telling Cards
weekly-fortune-telling-cards
Official Weekly Fortune Telling Cards plugin, supported by the PowerFortunes team. Fortune Telling Cards adds value and interesting content to your si …
WeekSync Scheduler
week-sync-scheduler
Automatically send weekly Gravity Forms entries reports via email with configurable schedule, recipients, and form selection.
Gravity Forms Periodic Notification E-Mails Developer Profile
3 plugins · 80 total installs
How We Detect Gravity Forms Periodic Notification E-Mails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-periodic-notification-e-mails-by-weptile/js/sack.js/wp-content/plugins/gravity-forms-periodic-notification-e-mails-by-weptile/js/sack.jsgravityforms.php?ver=tooltips.php?ver=admin.css?ver=HTML / DOM Fingerprints
wdgfm_settings_page<!-- end SelectExportForm --><!-- The following code can be used to display all the current schedule intervals --><!-- First parameter names the hook --><!-- Second parameter is the name of our function to call -->+1 moreid="wdgfm_settings_page"id="wdgfm_tasks_page"sack