Integration for Luminate and Gravity Forms Security & Risk Analysis

wordpress.org/plugins/integration-for-luminate-and-gravity-forms

This is a Gravity Forms Add-On to feed submission data from Gravity Forms into the Luminate Online Marketing platform (formerly known as Convio).

30 active installs v1.3.5 PHP 7.0+ WP 5.5+ Updated Jan 15, 2026
crmformsintegration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration for Luminate and Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Integration for Luminate and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

This plugin, "integration-for-luminate-and-gravity-forms" v1.3.5, presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, having no recorded vulnerabilities (CVEs), and not bundling any external libraries. The static analysis also indicates a low number of total flows analyzed by the taint analysis and no critical or high-severity taint flows, which is encouraging.

However, significant concerns arise from the attack surface. The plugin exposes a single AJAX handler that lacks authentication checks. This is a critical vulnerability as it allows any unauthenticated user to trigger this functionality, potentially leading to unauthorized actions. While the overall number of entry points is low, this single unprotected entry point is a major risk. The code also shows a concerning percentage of unescaped output (19%), which could be a vector for cross-site scripting (XSS) vulnerabilities, although no specific taint flows confirm this at a critical level.

The absence of any recorded vulnerabilities in its history, coupled with good SQL practices, suggests a generally well-maintained codebase in some areas. Nevertheless, the presence of an unprotected AJAX handler and the significant portion of unescaped output represent clear weaknesses that must be addressed to improve the plugin's overall security.

Key Concerns

  • AJAX handler without authentication
  • Significant portion of unescaped output
Vulnerabilities
None known

Integration for Luminate and Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Integration for Luminate and Gravity Forms Release Timeline

v1.3.5Current
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
v1.2.21
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.10
v1.1.9
v1.1.8
v1.1.7
v1.1.5
v1.1.4
v1.1.3
v1.1.2
Code Analysis
Analyzed Mar 16, 2026

Integration for Luminate and Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

81% escaped16 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ajax_load_survey_fields (inc\class-gf-luminate-survey.php:36)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Integration for Luminate and Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_get_luminate_survey_questionsinc\class-gf-luminate-survey.php:15
WordPress Hooks 12
actiongform_loadedgravityforms-luminate.php:25
actionadmin_initgravityforms-luminate.php:26
filtergform_input_masksgravityforms-luminate.php:102
actionadmin_noticesinc\class-gf-luminate-admin-notice.php:37
filtergf_luminate_feed_fieldsinc\class-gf-luminate-constituent.php:14
filtergf_luminate_feed_fieldsinc\class-gf-luminate-survey.php:16
filtergform_luminate_constituent_args_pre_postinc\class-gf-luminate-survey.php:317
filtergform_settings_save_buttoninc\class-gf-luminate.php:65
filtergform_predefined_choicesinc\class-gf-luminate.php:66
actionwp_http_luminate_request_failed_resultsinc\class-gf-luminate.php:67
actionwp_http_luminate_request_success_resultsinc\class-gf-luminate.php:68
actiongform_enqueue_scriptsinc\class-gf-luminate.php:69
Maintenance & Trust

Integration for Luminate and Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version7.0
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Integration for Luminate and Gravity Forms Developer Profile

cornershop

9 plugins · 11K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Luminate and Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/css/gf-luminate-admin.css/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/js/gf-luminate-admin.js/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/js/gf-luminate-constituent.js/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/js/gf-luminate-survey.js
Script Paths
https://cornershopcreative.com/assets/js/cornershop.js
Version Parameters
gravityforms-luminate/gravityforms-luminate.php?ver=

HTML / DOM Fingerprints

CSS Classes
gfluminate-cornershop-info
HTML Comments
<!-- Luminate API cache cleared -->
Data Attributes
data-gf-luminate-noncedata-gf-luminate-constituent-nonce
JS Globals
gf_luminate_constituent_ajax_objectgf_luminate_survey_ajax_object
REST Endpoints
/wp-json/gf_luminate/v1/clear_cache
FAQ

Frequently Asked Questions about Integration for Luminate and Gravity Forms