Integration for CardConnect and Gravity Forms Security & Risk Analysis

wordpress.org/plugins/integration-for-cardconnect-and-gravity-forms

Use CardConnect to process payments submitted via Gravity Forms.

100 active installs v1.3.0 PHP 7.0+ WP 3.6+ Updated Dec 3, 2025
crmformsintegration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Integration for CardConnect and Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for CardConnect and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "integration-for-cardconnect-and-gravity-forms" v1.3.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, including the complete absence of dangerous functions, file operations, and external HTTP requests. All SQL queries are secured using prepared statements, which is a significant strength. The plugin also has no recorded vulnerability history, suggesting a history of relatively secure development.

However, there are notable areas of concern. The most significant risk stems from the presence of an unprotected AJAX handler. This represents a direct entry point into the plugin that lacks any authentication or authorization checks, making it a prime target for attackers. While the static analysis did not uncover specific taint flows or vulnerabilities, the absence of nonce checks on this unprotected AJAX handler is a critical oversight. Furthermore, the output escaping, while mostly good, has a small percentage that is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities under specific conditions.

In conclusion, the plugin's lack of historical vulnerabilities and good SQL practices are commendable. However, the unprotected AJAX handler is a serious flaw that requires immediate attention. The absence of nonce checks exacerbates this risk. While the output escaping could be improved, the primary focus should be on securing the identified AJAX entry point.

Key Concerns

  • Unprotected AJAX handler detected
  • AJAX handler without nonce check
  • Some output not properly escaped
Vulnerabilities
None known

Integration for CardConnect and Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Integration for CardConnect and Gravity Forms Release Timeline

v1.3.0Current
v1.2.0
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Integration for CardConnect and Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
8 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

73% escaped11 total outputs
Attack Surface
1 unprotected

Integration for CardConnect and Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_gf_cardconnect_dismiss_sunset_warninggravityforms-cardconnect.php:36
WordPress Hooks 6
actiongfcardconnect_inquire_transactionclass-gravityforms-cardconnect.php:144
filtergform_export_fieldsclass-gravityforms-cardconnect.php:148
filtergform_export_field_valueclass-gravityforms-cardconnect.php:149
actiongform_loadedgravityforms-cardconnect.php:13
actionadmin_enqueue_scriptsgravityforms-cardconnect.php:34
actionadmin_noticesgravityforms-cardconnect.php:35
Maintenance & Trust

Integration for CardConnect and Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Integration for CardConnect and Gravity Forms Developer Profile

cornershop

9 plugins · 11K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Integration for CardConnect and Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-cardconnect-and-gravity-forms/admin.js
Script Paths
/wp-content/plugins/integration-for-cardconnect-and-gravity-forms/admin.js
Version Parameters
integration-for-cardconnect-and-gravity-forms/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf-cardconnect-sunset-warning
Data Attributes
data-gf-cardconnect-settings-page
JS Globals
gf_cardconnect_params
FAQ

Frequently Asked Questions about Integration for CardConnect and Gravity Forms