Gravity Forms Popup Widget Security & Risk Analysis

wordpress.org/plugins/gravity-forms-popup-widget

A widget to add Gravity Form in dialog popup, has an option to add a delay, a position, and an introduction page.

50 active installs v0.8 PHP + WP 3.2+ Updated Jan 31, 2014
dialoggravity-formsgravityformsjqueryuipopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms Popup Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Gravity Forms Popup Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The gravity-forms-popup-widget v0.8 plugin exhibits a concerning security posture despite the absence of known CVEs. The static analysis reveals a significant weakness in output escaping, with 0% of the 27 identified outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed within the user's browser. Furthermore, the complete lack of capability checks and nonce checks, combined with no registered entry points that require authentication, suggests that any functionality exposed by this plugin is likely accessible to unauthenticated users, further amplifying the XSS risk. The absence of any recorded vulnerabilities historically might lead to complacency, but it does not negate the current, evident code quality issues. While the plugin performs well in terms of SQL injection prevention and avoiding dangerous functions, the severe lack of output escaping and authorization controls presents a critical security gap. It is strongly recommended that this plugin be audited for proper output escaping and that robust authorization mechanisms be implemented before its use in a production environment.

Key Concerns

  • 0% properly escaped output
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

Gravity Forms Popup Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms Popup Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped27 total outputs
Attack Surface

Gravity Forms Popup Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitwidget.php:11
actionactivated_pluginwidget.php:12
actionadmin_noticeswidget.php:25
actionwidgets_initwidget.php:95
Maintenance & Trust

Gravity Forms Popup Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 31, 2014
PHP min version
Downloads13K

Community Trust

Rating20/100
Number of ratings2
Active installs50
Developer Profile

Gravity Forms Popup Widget Developer Profile

Alex (Shurf) Frenkel

3 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Popup Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gravity-forms-popup-widget/gf_popup_widget_script.js/wp-content/plugins/gravity-forms-popup-widget/gf_popup_widget_style.css
Script Paths
/wp-content/plugins/gravity-forms-popup-widget/gf_popup_widget_script.js
Version Parameters
gravity-forms-popup-widget/gf_popup_widget_script.js?ver=gravity-forms-popup-widget/gf_popup_widget_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
gform_popup_widgetgf_widget_btn
Data Attributes
data-delay
JS Globals
gform_popup_widget
FAQ

Frequently Asked Questions about Gravity Forms Popup Widget