
Gravity Forms – OTP Verification (SMS/EMAIL) Security & Risk Analysis
wordpress.org/plugins/gravity-otp-verificationA powerful plugin for Gravity Forms that adds OTP verification via SMS/Email to your forms for FREE.
Is Gravity Forms – OTP Verification (SMS/EMAIL) Safe to Use in 2026?
Generally Safe
Score 100/100Gravity Forms – OTP Verification (SMS/EMAIL) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gravity-otp-verification" plugin v3.2.0 exhibits a generally positive security posture based on the static analysis. A significant strength is the complete lack of any recorded vulnerabilities (CVEs), suggesting a history of responsible development and patching. The analysis also indicates no critical or high severity taint flows, which is excellent. Furthermore, the plugin demonstrates good practices in areas like output escaping (74% properly escaped) and the use of prepared statements for SQL queries (50%). The absence of dangerous functions and file operations further strengthens its security profile.
However, there are areas that warrant attention. While the total attack surface is relatively small with no unprotected entry points, the presence of 3 AJAX handlers could be a potential area for future concern if authentication mechanisms are not rigorously maintained. The 6 external HTTP requests also represent a minor external dependency that could be a vector if those external services are compromised or introduce vulnerabilities. Finally, the 50% usage of prepared statements for SQL queries, while not ideal, indicates that half of the SQL queries might be susceptible to SQL injection if not properly sanitized in their construction, though the taint analysis did not reveal any unsanitized flows in this version.
Overall, the plugin appears to be developed with security in mind, evidenced by its clean vulnerability history and good static analysis results in critical areas. The strengths significantly outweigh the weaknesses. The minor concerns revolve around potential future attack vectors related to AJAX handlers and external requests, and the room for improvement in SQL query sanitization.
Key Concerns
- SQL queries not using prepared statements
- External HTTP requests
- Bundled libraries (DataTables, Select2)
Gravity Forms – OTP Verification (SMS/EMAIL) Security Vulnerabilities
Gravity Forms – OTP Verification (SMS/EMAIL) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Gravity Forms – OTP Verification (SMS/EMAIL) Attack Surface
AJAX Handlers 3
Shortcodes 3
WordPress Hooks 18
Maintenance & Trust
Gravity Forms – OTP Verification (SMS/EMAIL) Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms – OTP Verification (SMS/EMAIL) Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
Gravity Forms – OTP Verification (SMS/EMAIL) Developer Profile
2 plugins · 80 total installs
How We Detect Gravity Forms – OTP Verification (SMS/EMAIL)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-otp-verification/assets/css/otp-style.css/wp-content/plugins/gravity-otp-verification/assets/js/otp-script.jswp-content/plugins/gravity-otp-verification/assets/js/otp-script.jsgravity-otp-verification/assets/css/otp-style.css?ver=gravity-otp-verification/assets/js/otp-script.js?ver=HTML / DOM Fingerprints
gform_otp_settings<!-- Unauthorized Access! --><!-- Gravity Forms - OTP Verification (SMS/EMAIL) :: Developed by <a href='https://pigment.dev/'>Pigment.Dev</a> --><!-- admin.php?page=gravity_otp_verification#tab_general -->data-field-iddata-form-iddata-page-iddata-otp-typegravity_otp_verification_vars/wp-json/gravity-otp-verification/v1/send_otp