
Gravity Forms / WooCommerce Recently Viewed Products Security & Risk Analysis
wordpress.org/plugins/gravity-forms-recently-viewed-productsAdds recently viewed products from WooCommerce to all Gravity Form submissions
Is Gravity Forms / WooCommerce Recently Viewed Products Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms / WooCommerce Recently Viewed Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Gravity Forms Recently Viewed Products plugin v1.1 exhibits a seemingly strong security posture at first glance, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface and no unprotected entry points. The code analysis also shows no dangerous functions, file operations, or external HTTP requests, and all SQL queries are prepared. However, a significant concern arises from the complete lack of output escaping, with 100% of identified outputs being unescaped. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-controlled data could be injected into the page without proper sanitization. Furthermore, the absence of nonce checks and capability checks, combined with the lack of taint analysis data, leaves potential for various other security weaknesses that are not immediately apparent but could be exploited if user input is not handled with extreme care throughout the plugin's execution. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, this does not negate the risks identified in the static analysis, particularly the unescaped output, which represents a direct and exploitable security flaw. In conclusion, while the plugin avoids common attack vectors and uses prepared statements for database interactions, the critical flaw of unescaped output presents a significant risk that needs immediate attention. The lack of comprehensive security checks like nonces and capability checks also leaves room for concern regarding its overall robustness.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Gravity Forms / WooCommerce Recently Viewed Products Security Vulnerabilities
Gravity Forms / WooCommerce Recently Viewed Products Code Analysis
Output Escaping
Gravity Forms / WooCommerce Recently Viewed Products Attack Surface
WordPress Hooks 5
Maintenance & Trust
Gravity Forms / WooCommerce Recently Viewed Products Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms / WooCommerce Recently Viewed Products Alternatives
Data8 Validation
data8-validation-for-contact-form-7
Applies Data8 Email, Unusable Name, Phone Validation and PredictiveAddress services to WooCommerce checkout, Gravity Forms and Contact Form 7, WPForms …
Data Soap Validation
data-soap-validation
Applies Data Soap telephone and email validation services to Contact Form 7, Elementor Pro, Gravity Forms, Woocommerce & WPForms Requires PHP
Payment4 Crypto Payment gateway
payment4-crypto-payment-gateway
Accept secure cryptocurrency payments in WooCommerce, Restrict Content Pro, Easy Digital Downloads, and Gravity Forms with Payment4.
Associate Gravity Forms with WooCommerce
associate-gravity-forms-with-products-for-woocommerce
Quickly and easily add a Gravity Form to your WooCommerce order complete / thank you page based on specific products.
mklasen's GF WC Country
mk-gf-wc-country
Make Gravity Forms use Woocommerce's list of countries.
Gravity Forms / WooCommerce Recently Viewed Products Developer Profile
7 plugins · 70 total installs
How We Detect Gravity Forms / WooCommerce Recently Viewed Products
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
postboxinside<div class='postbox' id='viewed-products'><h3 style='cursor:default'>Recently Viewed Products</h3><div class='inside'><ol>