Integration for Billingo & Gravity Forms Security & Risk Analysis

wordpress.org/plugins/integration-for-billingo-gravity-forms

Billingo összeköttetés Gravity Forms-hoz(nem hivatalos bővítmény)

10 active installs v1.0.10 PHP + WP 5.0+ Updated Unknown
billingogravity-formsmagyarszamlazo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration for Billingo & Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for Billingo & Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "integration-for-billingo-gravity-forms" plugin v1.0.10 exhibits a generally strong security posture based on the provided static analysis. The absence of critical or high severity taint flows, the consistent use of prepared statements for SQL queries, and a high percentage of properly escaped output are positive indicators. Furthermore, the presence of nonce and capability checks for the AJAX handlers suggests an effort to protect against common web vulnerabilities. The plugin's clean vulnerability history with no recorded CVEs further reinforces this positive assessment.

However, a few areas warrant attention. While the attack surface is relatively small with 6 AJAX handlers, the static analysis explicitly states that 0 are without auth checks, which is a strength. The presence of file operations and external HTTP requests, though not flagged as inherently vulnerable in the static analysis, represent potential vectors for attack if not meticulously handled. The data indicates 3 file operations and 3 external HTTP requests which, while not flagged as immediately dangerous, are points that would require deeper scrutiny in a more comprehensive audit to ensure proper sanitization and validation of any user-supplied input that might influence these operations.

In conclusion, this plugin appears to be developed with security in mind, demonstrating good practices in data handling and access control. The lack of historical vulnerabilities is a significant strength. The primary opportunities for concern lie in the potential for vulnerabilities within the file operations and external HTTP requests, which, although not identified as problematic in this analysis, are areas that always carry inherent risk and should be monitored closely in future updates. Overall, the current risk appears low.

Vulnerabilities
None known

Integration for Billingo & Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integration for Billingo & Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
63 escaped
Nonce Checks
7
Capability Checks
8
File Operations
3
External Requests
3
Bundled Libraries
0

Output Escaping

91% escaped69 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
pro_check (class-gf-billingo.php:1608)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for Billingo & Gravity Forms Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_gf_billingo_generate_invoiceclass-gf-billingo.php:109
authwp_ajax_gf_billingo_voidclass-gf-billingo.php:110
authwp_ajax_gf_billingo_completeclass-gf-billingo.php:111
authwp_ajax_gf_billingo_pro_checkclass-gf-billingo.php:112
authwp_ajax_gf_billingo_pro_deactivateclass-gf-billingo.php:113
authwp_ajax_gf_billingo_hide_noticeincludes\class-admin-notices.php:30
WordPress Hooks 13
filtergform_replace_merge_tagsclass-gf-billingo.php:43
actiongform_admin_pre_renderclass-gf-billingo.php:44
filtergform_entry_detail_meta_boxesclass-gf-billingo.php:91
filtergform_entry_list_columnsclass-gf-billingo.php:92
filtergform_entries_column_filterclass-gf-billingo.php:93
actiongform_post_payment_completedclass-gf-billingo.php:100
actiongform_after_submissionclass-gf-billingo.php:101
actionadmin_initincludes\class-admin-notices.php:27
actionadmin_initincludes\class-admin-notices.php:28
actionadmin_headincludes\class-admin-notices.php:29
actionadmin_noticesincludes\class-admin-notices.php:58
actionadmin_noticesincludes\class-admin-notices.php:63
actiongform_loadedindex.php:17
Maintenance & Trust

Integration for Billingo & Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Integration for Billingo & Gravity Forms Developer Profile

Viszt Péter

6 plugins · 16K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
478 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Billingo & Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-billingo-gravity-forms/assets/css/admin.css/wp-content/plugins/integration-for-billingo-gravity-forms/assets/images/ajax-loader.gif/wp-content/plugins/integration-for-billingo-gravity-forms/assets/js/admin.js/wp-content/plugins/integration-for-billingo-gravity-forms/assets/js/jquery-blockui/jquery.blockUI.js
Script Paths
/wp-content/plugins/integration-for-billingo-gravity-forms/assets/js/admin.js/wp-content/plugins/integration-for-billingo-gravity-forms/assets/js/jquery-blockui/jquery.blockUI.js
Version Parameters
integration-for-billingo-gravity-forms/assets/css/admin.css?ver=integration-for-billingo-gravity-forms/assets/js/admin.js?ver=integration-for-billingo-gravity-forms/assets/js/jquery-blockui/jquery.blockUI.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_billingo_pro_version_activegf_billingo_pro_alertdelete-alertalert_red
Data Attributes
data-nonce
JS Globals
window.gf_billingo_admin_strings
REST Endpoints
/wp-json/gf/v2/settings/billingo/wp-json/gf/v2/settings/billingo-pro-key/wp-json/gf/v2/settings/billingo-pro-email
FAQ

Frequently Asked Questions about Integration for Billingo & Gravity Forms