Integrate Instamojo with Gravity Forms Security & Risk Analysis

wordpress.org/plugins/integrate-instamojo-with-gravity-forms

With the Gravity Forms Instamojo Add-On, you can easily accept payments from over different payment methods, making it a great fit for any business wa …

10 active installs v1.0.0 PHP 5.6.0+ WP 3.9.2+ Updated Unknown
gravity-formsinstamojointegrate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integrate Instamojo with Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Integrate Instamojo with Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "integrate-instamojo-with-gravity-forms" v1.0.0 exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities, or unescaped output, which are common pitfalls for WordPress plugins. The complete absence of known CVEs and a clean vulnerability history further reinforces this impression of good development practices. However, several areas raise concerns. The lack of any capability checks or nonce checks, especially given the presence of two external HTTP requests, presents a potential risk. While the attack surface appears minimal with zero entry points detected, the absence of these fundamental security controls means that any code executed through these external requests could be vulnerable to unauthorized access or manipulation if not properly secured within the external service itself. The taint analysis revealing two flows with unsanitized paths, though not classified as critical or high severity, warrants attention. These could represent potential avenues for malicious data injection if not handled meticulously by the plugin's logic or the external services it interacts with.

In conclusion, the plugin demonstrates strengths in its handling of core WordPress security features like prepared statements and output escaping. The lack of past vulnerabilities is a significant positive. Nevertheless, the absence of capability checks, nonce checks, and the presence of unsanitized taint flows are notable weaknesses that, while not immediately critical, could be exploited in conjunction with other factors or future code changes. A score reduction is warranted to reflect these potential, albeit currently unproven, risks.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Two flows with unsanitized paths
  • External HTTP requests without auth checks
Vulnerabilities
None known

Integrate Instamojo with Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integrate Instamojo with Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
callback (class-gf-instamojo.php:561)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integrate Instamojo with Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actiongform_after_submissionclass-gf-instamojo.php:381
filtergform_notification_eventsclass-gf-instamojo.php:666
actiongform_loadedinstamojo.php:20
actionadmin_post_gf_instamojo_initinstamojo.php:21
filtergform_currenciesinstamojo.php:40
Maintenance & Trust

Integrate Instamojo with Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedUnknown
PHP min version5.6.0
Downloads763

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Integrate Instamojo with Gravity Forms Developer Profile

Scrippter

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integrate Instamojo with Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrate-instamojo-with-gravity-forms/assets/css/style.css/wp-content/plugins/integrate-instamojo-with-gravity-forms/assets/js/script.js
Script Paths
/wp-content/plugins/integrate-instamojo-with-gravity-forms/assets/js/script.js
Version Parameters
integrate-instamojo-with-gravity-forms/assets/css/style.css?ver=integrate-instamojo-with-gravity-forms/assets/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-gf_instamojo_feed_namedata-gf_instamojo_api_keydata-gf_instamojo_auth_tokendata-gf_instamojo_environmentdata-gf_instamojo_transaction_typedata-gf_instamojo_payment_amount+5 more
JS Globals
GF_Instamojo
FAQ

Frequently Asked Questions about Integrate Instamojo with Gravity Forms