
Global Payments SecureSubmit Addon for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/heartland-secure-submit-addon-for-gravity-formsSecureSubmit allows merchants to take PCI-Friendly Credit Card payments with Gravity Forms using Global Payments Payment Gateway.
Is Global Payments SecureSubmit Addon for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Global Payments SecureSubmit Addon for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'heartland-secure-submit-addon-for-gravity-forms' version 2.2.0 demonstrates several strong security practices. Notably, all SQL queries are executed using prepared statements, and all identified output is properly escaped, indicating a good defense against common injection and XSS vulnerabilities. The absence of any recorded CVEs or known vulnerabilities in its history further suggests a generally secure development and maintenance approach.
However, a significant concern arises from the static analysis. The plugin exposes a single AJAX handler that lacks any authentication checks. This unprotected entry point represents a direct attack vector that could be exploited by unauthenticated users to trigger unintended actions or potentially access sensitive information, depending on the functionality of that handler. The lack of nonce checks on this handler exacerbates this risk, as it offers no protection against Cross-Site Request Forgery (CSRF) attacks.
While the overall code quality appears high due to the absence of dangerous functions and well-handled SQL and output, the unprotected AJAX endpoint is a critical weakness. The plugin's vulnerability history is clean, which is a positive indicator, but it doesn't mitigate the immediate risk posed by the identified unprotected entry point. A balanced assessment highlights strong adherence to fundamental security principles in most areas, contrasted by a singular but significant flaw in authentication for its AJAX functionality.
Key Concerns
- AJAX handler without auth checks
- AJAX handler without nonce checks
Global Payments SecureSubmit Addon for Gravity Forms Security Vulnerabilities
Global Payments SecureSubmit Addon for Gravity Forms Code Analysis
Output Escaping
Global Payments SecureSubmit Addon for Gravity Forms Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Global Payments SecureSubmit Addon for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Global Payments SecureSubmit Addon for Gravity Forms Alternatives
Global Payments SecureSubmit Gateway
woocommerce-securesubmit-gateway
SecureSubmit allows merchants to take PCI-Friendly Credit Card payments using Global Payments Payment Gateway.
WP SecureSubmit
securesubmit
SecureSubmit allows merchants using Global Payments to take PCI-Friendly donations on their WordPress site.
گرویتی فرم فارسی
persian-gravity-forms
بسته کامل فارسی ساز گرویتی فرم
GravityExport Lite for Gravity Forms
gf-entries-in-excel
Export all Gravity Forms entries to Excel (.xlsx) or CSV via a download button or a secret shareable URL.
Multiple Columns for Gravity Forms
gf-form-multicolumn
Introduces new form elements into Gravity Forms which allow for simple column creation.
Global Payments SecureSubmit Addon for Gravity Forms Developer Profile
3 plugins · 740 total installs
How We Detect Global Payments SecureSubmit Addon for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/css/style.css/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/common.js/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/hps-credit-card.js/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/hps-ach.js/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/common.js/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/hps-credit-card.js/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/hps-ach.js/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/css/style.css?ver=/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/common.js?ver=/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/hps-credit-card.js?ver=/wp-content/plugins/heartland-secure-submit-addon-for-gravity-forms/assets/js/hps-ach.js?ver=HTML / DOM Fingerprints
hpsACHhpscreditcarddata-type='hpsACH'data-type='hpscreditcard'window.HpsCreditCardwindow.HpsAch/wp-json/gfsecuresubmit/v1/validate-secret-api-key