
GravityWP – Merge Tags Security & Risk Analysis
wordpress.org/plugins/gravitywp-merge-tagsAdds an admin page to show the merge tags and form information of a specific Gravity Form.
Is GravityWP – Merge Tags Safe to Use in 2026?
Generally Safe
Score 95/100GravityWP – Merge Tags has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of gravitywp-merge-tags v1.4.5 shows a generally good security posture with several positive indicators. The absence of dangerous functions, file operations, and external HTTP requests is a strong point. Furthermore, 100% of SQL queries utilize prepared statements, and nearly all output is properly escaped, minimizing common web vulnerabilities. The attack surface appears to be minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected.
However, two flows with unsanitized paths identified in the taint analysis are a significant concern. While classified as not critical or high severity, unsanitized paths can still lead to unpredictable behavior or security bypasses, especially if they interact with file system operations or user-controlled input in ways not immediately apparent. The vulnerability history reveals a past critical vulnerability related to PHP Remote File Inclusion, which is a severe type of flaw. Although there are no currently unpatched vulnerabilities, this history suggests a potential for developing such critical issues if input validation and sanitization are not rigorously maintained.
In conclusion, gravitywp-merge-tags v1.4.5 demonstrates good practices in several areas, particularly in its handling of SQL and output. The minimal attack surface is also a positive. The primary areas for improvement are addressing the identified unsanitized paths and being vigilant about preventing critical vulnerabilities like Remote File Inclusion, which has occurred in the past.
Key Concerns
- Flows with unsanitized paths detected
- Past critical vulnerability (RFI)
GravityWP – Merge Tags Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GravityWP - Merge Tags <= 1.4.4 - Unauthenticated Local File Inclusion
GravityWP – Merge Tags Code Analysis
Output Escaping
Data Flow Analysis
GravityWP – Merge Tags Attack Surface
WordPress Hooks 4
Maintenance & Trust
GravityWP – Merge Tags Maintenance & Trust
Maintenance Signals
Community Trust
GravityWP – Merge Tags Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
GravityWP – Merge Tags Developer Profile
4 plugins · 9K total installs
How We Detect GravityWP – Merge Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravitywp-merge-tags/assets/img/gravitywp-logo.svg/wp-content/plugins/gravitywp-merge-tags/assets/img/gwp_astronaut2.svg/wp-content/plugins/gravitywp-merge-tags/gravitywp-merge-tags.php/wp-content/plugins/gravitywp-merge-tags/class-gwp-mergetags.phpgravitywp-merge-tags/gravitywp-merge-tags.php?ver=1.4.5class-gwp-mergetags.php?ver=1.4.5HTML / DOM Fingerprints
gf_form_toolbar_custom_linkgravitywp-logogwp_astronaut2.svg<span style="font-size:15px;font-weight: 700;">{ }</span>