
Importer for Gravity Forms and NationBuilder Security & Risk Analysis
wordpress.org/plugins/importer-for-gravity-forms-and-nationbuilderAutomatically import entries from Gravity Forms into NationBuilder.
Is Importer for Gravity Forms and NationBuilder Safe to Use in 2026?
Generally Safe
Score 85/100Importer for Gravity Forms and NationBuilder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, this plugin exhibits a generally strong security posture. There are no identified dangerous functions, no raw SQL queries, and a lack of critical or high-severity taint flows. The absence of known CVEs and a recorded vulnerability history further contribute to this positive assessment. However, there are notable areas for improvement. The plugin has a 40% rate of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Additionally, the absence of nonce checks and capability checks for any potential entry points (even though none were explicitly found in this analysis, it's a concerning pattern if entry points were to be added later) raises concerns about the plugin's resilience against brute-force attacks or unauthorized actions. The single external HTTP request also warrants scrutiny to ensure it is handled securely and does not expose the site to external threats. While the plugin demonstrates good practices in many areas, the potential for unescaped output and the lack of robust authorization mechanisms for potential future additions are key areas that need attention to improve its overall security.
Key Concerns
- 40% of outputs are not properly escaped
- No nonce checks found
- No capability checks found
- One external HTTP request identified
Importer for Gravity Forms and NationBuilder Security Vulnerabilities
Importer for Gravity Forms and NationBuilder Code Analysis
Output Escaping
Importer for Gravity Forms and NationBuilder Attack Surface
WordPress Hooks 3
Maintenance & Trust
Importer for Gravity Forms and NationBuilder Maintenance & Trust
Maintenance Signals
Community Trust
Importer for Gravity Forms and NationBuilder Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
Importer for Gravity Forms and NationBuilder Developer Profile
3 plugins · 530 total installs
How We Detect Importer for Gravity Forms and NationBuilder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/importer-for-gravity-forms-and-nationbuilder/css/gf-nb-importer-admin.css/wp-content/plugins/importer-for-gravity-forms-and-nationbuilder/js/gf-nb-importer-admin.jsgf-nb-importer/css/gf-nb-importer-admin.css?ver=gf-nb-importer/js/gf-nb-importer-admin.js?ver=HTML / DOM Fingerprints
gf_nb_importer_settings_fieldsdata-gf-nb-importer-settingsgf_nb_importer_scripts_params/wp-json/gf_nb_importer/v1/oauth_callback/