
Add-On for Zoom Registration and Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gravity-zwrRegister attendees in your Zoom Webinar or Zoom Meeting through a Gravity Form.
Is Add-On for Zoom Registration and Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Add-On for Zoom Registration and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Gravity-ZWR plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests not properly handled suggests good development practices. The plugin also demonstrates a lack of critical or high-severity taint flows, indicating that user input is not being improperly processed within the analyzed code. Furthermore, the plugin's vulnerability history is completely clear, with no recorded CVEs of any severity. This suggests a commitment to security by the developers or a lack of past exploitation.
However, the static analysis also reveals several areas that, while not indicating immediate vulnerabilities, warrant attention. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, while reducing the attack surface to zero, might also indicate limited functionality. More importantly, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While the attack surface is reported as zero, if any future functionality were to be added that involved user interaction, the absence of these fundamental WordPress security mechanisms would create a direct path for various attacks. The presence of two external HTTP requests, without explicit details on their handling, also introduces a potential point of failure or risk if not implemented securely.
In conclusion, Gravity-ZWR appears to be a secure plugin in its current state, with excellent coding practices and no known vulnerabilities. The primary weakness lies in the fundamental absence of security checks like nonces and capability checks, which are essential for future extensibility and to protect against common WordPress attack vectors. While the current attack surface is zero, this lack of built-in security mechanisms presents a latent risk should the plugin evolve or if hidden entry points exist that were not detected by this analysis.
Key Concerns
- No nonce checks found
- No capability checks found
- Two external HTTP requests detected
Add-On for Zoom Registration and Gravity Forms Security Vulnerabilities
Add-On for Zoom Registration and Gravity Forms Code Analysis
Output Escaping
Add-On for Zoom Registration and Gravity Forms Attack Surface
WordPress Hooks 2
Maintenance & Trust
Add-On for Zoom Registration and Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Add-On for Zoom Registration and Gravity Forms Alternatives
Video Conferencing with Zoom
video-conferencing-with-zoom-api
Gives you the power to manage Zoom Meetings, Zoom Webinars, Recordings, Reports and create users directly from your WordPress dashboard.
MeetingHub for Zoom Meeting, Google Meet, Jitsi Meet, Webex, & Microsoft Teams | The All-in-One Webinar & Video Conference Solution
meetinghub
Meeting plugin to create instant webinars and meetings with Zoom Meeting, Google Meet, Jitsi Meet, Webex, & Microsoft Teams.
GoToWebinar Registration
gtwregister
This WordPress plugin background registers folks for a GoToWebinar right from your WordPress site.
Zoom for WordPress
wp-zoom
Sell, display, register users for webinars with Zoom for WordPress
ZD Embed for Zoom Meeting SDK
zd-embed-for-zoom-meeting-sdk
Embed meetings in WordPress using the Zoom Meeting SDK (Web) with secure server-side signature generation. This plugin is not affiliated with Zoom.
Add-On for Zoom Registration and Gravity Forms Developer Profile
12 plugins · 2K total installs
How We Detect Add-On for Zoom Registration and Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravity-zwr/assets/css/gravityzwr.css/wp-content/plugins/gravity-zwr/assets/js/gravityzwr.js/wp-content/plugins/gravity-zwr/assets/js/gravityzwr.jsgravity-zwr/assets/css/gravityzwr.css?ver=gravity-zwr/assets/js/gravityzwr.js?ver=HTML / DOM Fingerprints
gravityzwr-settings-page<!-- Require Gravity Forms Notice -->data-gravityzwr-field-iddata-gravityzwr-zoom-field-idgravityzwr_admin_params