Gravity Forms – Placeholders add-on Security & Risk Analysis

wordpress.org/plugins/gravity-forms-placeholders

Adds HTML5 placeholder support to Gravity Forms' fields with a Javascript fallback. Javascript & jQuery are required.

2K active installs v1.2.1 PHP + WP 3.0+ Updated Nov 28, 2017
formsgravitygravityformshtml5placeholders
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms – Placeholders add-on Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms – Placeholders add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of gravity-forms-placeholders v1.2.1 reveals a generally positive security posture. The plugin demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no file operations or external HTTP requests. Furthermore, the lack of any recorded CVEs or past vulnerabilities suggests a history of secure development. However, a significant concern arises from the complete lack of output escaping, indicating that any dynamic data displayed by the plugin is not being properly sanitized, potentially exposing users to Cross-Site Scripting (XSS) attacks if user-supplied data is reflected directly into the output. The absence of nonce checks and capability checks on any potential entry points, although the entry point count is currently zero, also presents a potential weakness should the plugin's functionality evolve without these security measures being implemented.

While the plugin currently has no apparent attack surface and a clean vulnerability history, the unescaped output is a critical oversight. This indicates that the plugin, despite its apparent simplicity and lack of known vulnerabilities, is susceptible to a common and dangerous class of web attacks. The absence of capability checks and nonces further contributes to this risk, as it means that even if new entry points were introduced, they might not be adequately protected against unauthorized access or manipulation. The current security is largely based on the absence of exposed functionality rather than proactive defense mechanisms.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

Gravity Forms – Placeholders add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms – Placeholders add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Gravity Forms – Placeholders add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_print_scriptsgravityforms-placeholders.php:18
Maintenance & Trust

Gravity Forms – Placeholders add-on Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedNov 28, 2017
PHP min version
Downloads52K

Community Trust

Rating98/100
Number of ratings24
Active installs2K
Developer Profile

Gravity Forms – Placeholders add-on Developer Profile

neojp

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms – Placeholders add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-placeholders/gf.placeholders.js/wp-content/plugins/gravity-forms-placeholders/jquery.placeholder-1.0.1.js
Script Paths
/wp-content/plugins/gravity-forms-placeholders/gf.placeholders.js/wp-content/plugins/gravity-forms-placeholders/jquery.placeholder-1.0.1.js

HTML / DOM Fingerprints

JS Globals
jquery_placeholder_url
FAQ

Frequently Asked Questions about Gravity Forms – Placeholders add-on