
Integration for Luminate and Gravity Forms Security & Risk Analysis
wordpress.org/plugins/integration-for-luminate-and-gravity-formsThis is a Gravity Forms Add-On to feed submission data from Gravity Forms into the Luminate Online Marketing platform (formerly known as Convio).
Is Integration for Luminate and Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Integration for Luminate and Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, "integration-for-luminate-and-gravity-forms" v1.3.5, presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, having no recorded vulnerabilities (CVEs), and not bundling any external libraries. The static analysis also indicates a low number of total flows analyzed by the taint analysis and no critical or high-severity taint flows, which is encouraging.
However, significant concerns arise from the attack surface. The plugin exposes a single AJAX handler that lacks authentication checks. This is a critical vulnerability as it allows any unauthenticated user to trigger this functionality, potentially leading to unauthorized actions. While the overall number of entry points is low, this single unprotected entry point is a major risk. The code also shows a concerning percentage of unescaped output (19%), which could be a vector for cross-site scripting (XSS) vulnerabilities, although no specific taint flows confirm this at a critical level.
The absence of any recorded vulnerabilities in its history, coupled with good SQL practices, suggests a generally well-maintained codebase in some areas. Nevertheless, the presence of an unprotected AJAX handler and the significant portion of unescaped output represent clear weaknesses that must be addressed to improve the plugin's overall security.
Key Concerns
- AJAX handler without authentication
- Significant portion of unescaped output
Integration for Luminate and Gravity Forms Security Vulnerabilities
Integration for Luminate and Gravity Forms Release Timeline
Integration for Luminate and Gravity Forms Code Analysis
Output Escaping
Data Flow Analysis
Integration for Luminate and Gravity Forms Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Integration for Luminate and Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Integration for Luminate and Gravity Forms Alternatives
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
Connector for Gravity Forms and Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-dynamics-crm
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to dynamics crm Online.
WP Gravity Forms Dynamics CRM
gf-dynamics-crm
Gravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
Caldera Forms CiviCRM
cf-civicrm
Integrate CiviCRM entities with Caldera Forms.
Integration for Luminate and Gravity Forms Developer Profile
9 plugins · 11K total installs
How We Detect Integration for Luminate and Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/css/gf-luminate-admin.css/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/js/gf-luminate-admin.js/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/js/gf-luminate-constituent.js/wp-content/plugins/integration-for-luminate-and-gravity-forms/assets/js/gf-luminate-survey.jshttps://cornershopcreative.com/assets/js/cornershop.jsgravityforms-luminate/gravityforms-luminate.php?ver=HTML / DOM Fingerprints
gfluminate-cornershop-info<!-- Luminate API cache cleared -->data-gf-luminate-noncedata-gf-luminate-constituent-noncegf_luminate_constituent_ajax_objectgf_luminate_survey_ajax_object/wp-json/gf_luminate/v1/clear_cache