Integration for Gravity Forms and Pipedrive Security & Risk Analysis

wordpress.org/plugins/integration-for-gravity-forms-and-pipedrive

Gravity Forms Pipedrive Plugin allows you to quickly integrate Gravity Forms with Pipedrive.

200 active installs v1.1.9 PHP 5.3+ WP 3.8+ Updated Dec 15, 2025
gravity-forms-pipedrivegravity-forms-pipedrive-integrationgravity-forms-to-pipedrivepipedrive
100
A · Safe
CVEs total1
Unpatched0
Last CVEAug 26, 2021
Safety Verdict

Is Integration for Gravity Forms and Pipedrive Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for Gravity Forms and Pipedrive has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 26, 2021Updated 3mo ago
Risk Assessment

The "integration-for-gravity-forms-and-pipedrive" plugin v1.1.9 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and proper output escaping, there are significant concerns. The analysis reveals a single unprotected AJAX handler, representing a direct entry point into the application that lacks authentication. Furthermore, a critical severity taint flow indicates a potential for serious security issues where unsanitized user input could be passed to a sensitive function. The plugin's vulnerability history shows one past medium-severity Cross-Site Scripting (XSS) vulnerability, which, although patched, suggests a prior weakness in input sanitization or output encoding.

Overall, the presence of an unprotected AJAX endpoint combined with a critical taint flow presents a notable risk. The past XSS vulnerability, though resolved, highlights a potential area for recurring issues if not diligently managed. While the plugin shows strengths in its use of prepared statements and output escaping, these are overshadowed by the identified direct attack vector and the critical taint flow. Mitigation of the unprotected AJAX handler and thorough investigation and remediation of the critical taint flow are paramount to improving the plugin's security.

Key Concerns

  • Unprotected AJAX handler
  • Critical severity taint flow
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Integration for Gravity Forms and Pipedrive Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-integration-for-gravity-forms-and-pipedrivemedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.0.7 (880d)
Code Analysis
Analyzed Mar 16, 2026

Integration for Gravity Forms and Pipedrive Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
17 prepared
Unescaped Output
100
398 escaped
Nonce Checks
19
Capability Checks
28
File Operations
2
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

68% prepared25 total queries

Output Escaping

80% escaped498 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<plugin-pages> (includes\plugin-pages.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Integration for Gravity Forms and Pipedrive Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_vxg_pipedrive_review_dismisswp\crmperks-notices.php:19
WordPress Hooks 34
actiongform_entry_detail_content_afterincludes\crmperks-gf.php:11
filtergform_tooltipsincludes\edit-form.php:14
actiongform_editor_jsincludes\edit-form.php:15
actiongform_field_standard_settingsincludes\edit-form.php:16
actionadmin_headincludes\edit-form.php:17
filtergform_admin_pre_renderincludes\edit-form.php:25
filtergform_pre_renderincludes\edit-form.php:26
actionadmin_enqueue_scriptsincludes\plugin-pages.php:32
filtergform_tooltipsincludes\plugin-pages.php:36
filtergform_logging_supportedincludes\plugin-pages.php:41
actiongform_form_settings_menuincludes\plugin-pages.php:42
filteradmin_menuincludes\plugin-pages.php:44
actiongform_post_note_addedincludes\plugin-pages.php:46
actiongform_pre_note_deletedincludes\plugin-pages.php:47
actiongform_update_statusincludes\plugin-pages.php:50
actiongform_after_update_entryincludes\plugin-pages.php:52
actiongform_entry_detail_sidebar_middleincludes\plugin-pages.php:53
actiongform_entry_infoincludes\plugin-pages.php:54
actionadmin_noticesincludes\plugin-pages.php:56
filterplugin_action_linksincludes\plugin-pages.php:57
actionplugins_loadedintegration-for-gravity-forms-and-pipedrive.php:61
actionadmin_noticesintegration-for-gravity-forms-and-pipedrive.php:76
actiongform_entry_createdintegration-for-gravity-forms-and-pipedrive.php:109
actiongform_post_add_entryintegration-for-gravity-forms-and-pipedrive.php:111
actiongform_post_payment_completedintegration-for-gravity-forms-and-pipedrive.php:115
actiongform_after_submissionintegration-for-gravity-forms-and-pipedrive.php:117
filtergform_confirmationintegration-for-gravity-forms-and-pipedrive.php:121
actioninitintegration-for-gravity-forms-and-pipedrive.php:124
actionadd_section_vxg_pipedrivewp\crmperks-notices.php:14
actionadd_section_mapping_vxg_pipedrivewp\crmperks-notices.php:15
filterplugin_row_metawp\crmperks-notices.php:16
filteradmin_footer_textwp\crmperks-notices.php:22
filtermenu_links_vxg_pipedrivewp\crmperks-notices.php:23
filtertab_contents_vxg_pipedrivewp\crmperks-notices.php:24
Maintenance & Trust

Integration for Gravity Forms and Pipedrive Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 15, 2025
PHP min version5.3
Downloads9K

Community Trust

Rating100/100
Number of ratings11
Active installs200
Developer Profile

Integration for Gravity Forms and Pipedrive Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Gravity Forms and Pipedrive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/assets/css/gf-pipedrive-admin.css/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/assets/css/gf-pipedrive-style.css/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/assets/js/gf-pipedrive-admin.js/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/assets/js/gf-pipedrive-scripts.js/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/includes/plugin-pages.php/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/includes/crmperks-gf.php
Script Paths
/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/assets/js/gf-pipedrive-admin.js/wp-content/plugins/integration-for-gravity-forms-and-pipedrive/assets/js/gf-pipedrive-scripts.js
Version Parameters
integration-for-gravity-forms-and-pipedrive/assets/css/gf-pipedrive-admin.css?ver=integration-for-gravity-forms-and-pipedrive/assets/css/gf-pipedrive-style.css?ver=integration-for-gravity-forms-and-pipedrive/assets/js/gf-pipedrive-admin.js?ver=integration-for-gravity-forms-and-pipedrive/assets/js/gf-pipedrive-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_pipedrive_form_container
HTML Comments
<!-- Gravity Forms Pipedrive Plugin --><!-- Start of GF Pipedrive Pro Settings -->
Data Attributes
data-pipedrive-form-iddata-pipedrive-feed-id
JS Globals
vxg_gf_pipedrive_admin_paramsvxg_gf_pipedrive_scripts_params
REST Endpoints
/wp-json/gf-pipedrive/v1/settings/wp-json/gf-pipedrive/v1/feeds
Shortcode Output
[gf_pipedrive_form_settings]
FAQ

Frequently Asked Questions about Integration for Gravity Forms and Pipedrive