
GravityWP – Count Security & Risk Analysis
wordpress.org/plugins/gravitywp-countCount, filter and display the number of Gravity Forms entries or the total of a number field for multiple entries.
Is GravityWP – Count Safe to Use in 2026?
Generally Safe
Score 100/100GravityWP – Count has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gravitywp-count v0.9.15 plugin exhibits a generally strong security posture based on the provided static analysis. There are no reported vulnerabilities in its history, and the code analysis reveals no dangerous functions, file operations, external HTTP requests, or raw SQL queries. All SQL queries utilize prepared statements, and all identified output points are properly escaped, which are excellent security practices.
The primary concern, however, lies in the absence of nonce and capability checks. With two entry points (shortcodes), the lack of these fundamental WordPress security mechanisms leaves the plugin susceptible to Cross-Site Request Forgery (CSRF) and potential unauthorized actions if these shortcodes handle sensitive operations. The static analysis indicates zero unprotected entry points, which is misleading given the absence of these crucial checks. The total absence of taint analysis flows is also notable, although this could be due to the plugin's limited functionality or the specific scope of the analysis.
While the plugin benefits from a clean vulnerability history and adherence to good practices like prepared statements and output escaping, the missing nonce and capability checks are significant security oversights. The plugin's otherwise clean record suggests it may be less complex or intentionally designed with limited functionality, but this does not excuse the lack of basic security controls for its exposed entry points. Therefore, while the current risk appears low due to the apparent limited functionality, the potential for exploitation exists.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
GravityWP – Count Security Vulnerabilities
GravityWP – Count Code Analysis
Output Escaping
GravityWP – Count Attack Surface
Shortcodes 2
Maintenance & Trust
GravityWP – Count Maintenance & Trust
Maintenance Signals
Community Trust
GravityWP – Count Alternatives
Country and State Selection Addon for Gravity Forms
gforms-addon-for-country-and-state-selection
Country and State Selection Addon for Gravity Forms lets you easily add dynamic country and state dropdown fields to your Gravity Forms.
mklasen's GF WC Country
mk-gf-wc-country
Make Gravity Forms use Woocommerce's list of countries.
ForgePress Country Choice Rules for Gravity Forms
forgepress-country-choice-rules-for-gravity-forms
Country-based choice rules for Gravity Forms. Hide or replace field choices per country, with optional VPN/Proxy handling.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
GravityWP – Count Developer Profile
4 plugins · 9K total installs
How We Detect GravityWP – Count
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravitywp-count/css/gravitywp-count.css/wp-content/plugins/gravitywp-count/js/gravitywp-count.js/wp-content/plugins/gravitywp-count/js/gravitywp-count.jsgravitywp-count/css/gravitywp-count.css?ver=gravitywp-count/js/gravitywp-count.js?ver=HTML / DOM Fingerprints
[gravitywp_count