IDPay For Wp Gravity Forms Security & Risk Analysis

wordpress.org/plugins/idpay-gateway-gravity-forms

After installing and enabling this plugin, your customers can pay through IDPay gateway.

100 active installs v3.1.1 PHP + WP + Updated Dec 9, 2023
gatewaygravity-formsgravityformsidpaypayment
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IDPay For Wp Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

IDPay For Wp Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'idpay-gateway-gravity-forms' plugin version 3.1.1 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and not performing file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of past development attention to security. However, there are significant concerns primarily stemming from the attack surface. The plugin exposes a single AJAX handler which lacks any authentication checks. This is a critical weakness as it means any unauthenticated user could potentially interact with this handler, leading to unintended actions or information disclosure if the handler is not designed with extreme care. The limited output escaping (6%) is also a concern, although the taint analysis did not reveal any issues, suggesting that while outputs might not be properly escaped, they might not be directly exposed to malicious input in a way that leads to exploitation through this plugin alone.

Despite the positive aspects like secure SQL and lack of known vulnerabilities, the unprotected AJAX endpoint is a substantial risk. This single point of entry without authentication represents a direct path for potential exploitation. While the plugin has a clean vulnerability history, this does not negate the immediate risk posed by the current code's exposed functionality. The low percentage of properly escaped output, though not leading to immediate critical findings in taint analysis, is a good practice that should be addressed to further harden the plugin. Overall, the plugin has some strong security foundations but requires immediate attention to secure its AJAX endpoint to mitigate the identified risk.

Key Concerns

  • AJAX handler without authentication
  • Low percentage of properly escaped output
Vulnerabilities
None known

IDPay For Wp Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IDPay For Wp Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
132
9 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped141 total outputs
Attack Surface
1 unprotected

IDPay For Wp Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_gf_IDPay_update_feed_activeidpay-gravity-forms.php:56
WordPress Hooks 17
actioninitidpay-gravity-forms.php:20
actionadmin_noticesidpay-gravity-forms.php:43
actionadmin_noticesidpay-gravity-forms.php:48
filtermembers_get_capabilitiesidpay-gravity-forms.php:52
filtergform_addon_navigationidpay-gravity-forms.php:57
actiongform_entry_infoidpay-gravity-forms.php:58
actiongform_after_update_entryidpay-gravity-forms.php:59
filtergform_form_settings_menuidpay-gravity-forms.php:62
actiongform_form_settings_page_IDPayidpay-gravity-forms.php:63
filtergform_disable_post_creationidpay-gravity-forms.php:85
filtergform_is_delayed_pre_process_feedidpay-gravity-forms.php:86
filtergform_confirmationidpay-gravity-forms.php:87
actionwpidpay-gravity-forms.php:88
filtergform_submit_buttonidpay-gravity-forms.php:89
filtergform_logging_supportedidpay-gravity-forms.php:92
filtergf_payment_gatewaysidpay-gravity-forms.php:93
filtergform_admin_pre_renderidpay-gravity-forms.php:96
Maintenance & Trust

IDPay For Wp Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 9, 2023
PHP min version
Downloads7K

Community Trust

Rating20/100
Number of ratings1
Active installs100
Developer Profile

IDPay For Wp Gravity Forms Developer Profile

IDPay

7 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IDPay For Wp Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/idpay-gateway-gravity-forms/assets/js/idpay-gravity-forms.js/wp-content/plugins/idpay-gateway-gravity-forms/assets/css/idpay-gravity-forms.css
Script Paths
/wp-content/plugins/idpay-gateway-gravity-forms/assets/js/idpay-gravity-forms.js
Version Parameters
idpay-gravity-forms/assets/js/idpay-gravity-forms.js?ver=idpay-gravity-forms/assets/css/idpay-gravity-forms.css?ver=

HTML / DOM Fingerprints

CSS Classes
idpay-gravity-forms-style
HTML Comments
<!-- IDPay Payment Data --><!-- IDPay Payment Meta -->
Data Attributes
data-idpay-actiondata-idpay-gateway
JS Globals
gform.addFilter('gform_merge_tags')
Shortcode Output
<div class="idpay-gravity-forms-style">
FAQ

Frequently Asked Questions about IDPay For Wp Gravity Forms