
Gravity Forms Sticky Form Security & Risk Analysis
wordpress.org/plugins/gravity-forms-sticky-formA plugin that makes your Gravity Forms stick!
Is Gravity Forms Sticky Form Safe to Use in 2026?
Generally Safe
Score 85/100Gravity Forms Sticky Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the gravity-forms-sticky-form plugin v1.0.5 reveals a generally strong security posture, with no apparent attack surface exposed through common entry points like AJAX handlers, REST API routes, or shortcodes. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and properly escaping all outputs. Furthermore, there are no recorded vulnerabilities in its history, suggesting a history of stable and secure development.
However, the presence of two instances of the `unserialize` function without any apparent checks or sanitization presents a significant concern. The `unserialize` function is notoriously dangerous when used with untrusted input, as it can lead to Remote Code Execution (RCE) if an attacker can control the serialized data. The lack of any nonce checks or capability checks on entry points, while not explicitly problematic given the zero entry points, means that if any were introduced in the future without proper checks, they would be vulnerable. The absence of taint analysis results is also noted; while it might indicate no issues were found, it could also mean the analysis was incomplete or not performed.
In conclusion, while the plugin exhibits several positive security indicators, the identified risk associated with `unserialize` is a critical weakness that could be exploited. The lack of historical vulnerabilities is a good sign, but it does not mitigate the inherent danger of the `unserialize` function without proper input validation. Developers should prioritize addressing this potential RCE vector.
Key Concerns
- Use of unserialize without sanitization
- Lack of nonce checks on entry points
- Lack of capability checks on entry points
Gravity Forms Sticky Form Security Vulnerabilities
Gravity Forms Sticky Form Code Analysis
Dangerous Functions Found
Gravity Forms Sticky Form Attack Surface
WordPress Hooks 5
Maintenance & Trust
Gravity Forms Sticky Form Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms Sticky Form Alternatives
Gravity Forms Data Persistence Add-On Reloaded
gravity-forms-data-persistence-add-on-reloaded
This plugin makes your Gravity Forms data-persistent.
Gravity Forms Data Persistence Add-On
gravity-forms-data-persistence-add-on
This plugin makes your Gravity Forms data-persistent.
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Smart phone field for Gravity Forms
smart-phone-field-for-gravity-forms
A simple and nice plugin to get auto country flag from user ip address on gravity form phone field.
Gravity Slider Fields
gravity-slider-fields
Adds slider fields to Gravity Forms
Gravity Forms Sticky Form Developer Profile
1 plugin · 50 total installs
How We Detect Gravity Forms Sticky Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-forms-sticky-form/gravity-forms-sticky-form.phpHTML / DOM Fingerprints
sticky_getEntryOptionKeyForGF