Integration for Szamlazz.hu & Gravity Forms Security & Risk Analysis

wordpress.org/plugins/integration-for-szamlazz-hu-gravity-forms

Számlázz.hu összeköttetés Gravity Forms-hoz.

80 active installs v1.3 PHP + WP 5.0+ Updated Feb 12, 2025
gravity-formsmagyarszamlazoszamlazzszamlazz-hu
91
A · Safe
CVEs total1
Unpatched0
Last CVESep 14, 2022
Safety Verdict

Is Integration for Szamlazz.hu & Gravity Forms Safe to Use in 2026?

Generally Safe

Score 91/100

Integration for Szamlazz.hu & Gravity Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 14, 2022Updated 1yr ago
Risk Assessment

The 'integration-for-szamlazz-hu-gravity-forms' plugin version 1.3 exhibits a generally good security posture, with no critical or high severity vulnerabilities found in taint analysis and all SQL queries using prepared statements. The presence of numerous capability checks and nonce checks on its AJAX endpoints further strengthens its defenses. However, a significant concern arises from the high percentage of improperly escaped output (55%), which could lead to various client-side vulnerabilities like Cross-Site Scripting (XSS) if user-supplied data is not handled carefully before rendering. Additionally, the plugin has a history of known vulnerabilities, including a high-severity one, indicating a past struggle with secure coding practices. While the current version appears to have addressed past vulnerabilities, the output escaping issue is a recurring theme that requires attention for a more robust security profile. The plugin demonstrates strengths in authentication and database query safety, but weaknesses in output sanitization and a history of past issues warrant vigilance.

Key Concerns

  • High percentage of unescaped output
  • Past high-severity vulnerability
Vulnerabilities
1

Integration for Szamlazz.hu & Gravity Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2022-3154high · 8.8Cross-Site Request Forgery (CSRF)

Multiple Plugins from Viszt Peter - Cross-Site Request Forgery

Sep 14, 2022 Patched in 1.2.7 (496d)
Code Analysis
Analyzed Mar 16, 2026

Integration for Szamlazz.hu & Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
31 escaped
Nonce Checks
9
Capability Checks
10
File Operations
7
External Requests
4
Bundled Libraries
0

Output Escaping

45% escaped69 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
generate_receipt_with_ajax (class-gf-szamlazz.php:1635)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for Szamlazz.hu & Gravity Forms Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_gf_szamlazz_generate_invoiceclass-gf-szamlazz.php:112
authwp_ajax_gf_szamlazz_sztornoclass-gf-szamlazz.php:113
authwp_ajax_gf_szamlazz_completeclass-gf-szamlazz.php:114
authwp_ajax_gf_szamlazz_generate_receiptclass-gf-szamlazz.php:115
authwp_ajax_gf_szamlazz_sztorno_receiptclass-gf-szamlazz.php:116
authwp_ajax_gf_szamlazz_pro_checkclass-gf-szamlazz.php:117
authwp_ajax_gf_szamlazz_pro_deactivateclass-gf-szamlazz.php:118
authwp_ajax_gf_szamlazz_hide_noticeincludes\class-admin-notices.php:36
WordPress Hooks 14
filtergform_replace_merge_tagsclass-gf-szamlazz.php:47
actiongform_admin_pre_renderclass-gf-szamlazz.php:48
filtergform_entry_detail_meta_boxesclass-gf-szamlazz.php:95
filtergform_entry_list_columnsclass-gf-szamlazz.php:96
filtergform_entries_column_filterclass-gf-szamlazz.php:97
actionafter_plugin_rowclass-gf-szamlazz.php:98
actiongform_post_payment_completedclass-gf-szamlazz.php:104
actiongform_after_submissionclass-gf-szamlazz.php:105
actionadmin_initincludes\class-admin-notices.php:33
actionadmin_initincludes\class-admin-notices.php:34
actionadmin_headincludes\class-admin-notices.php:35
actionadmin_noticesincludes\class-admin-notices.php:64
actionadmin_noticesincludes\class-admin-notices.php:69
actiongform_loadedindex.php:41
Maintenance & Trust

Integration for Szamlazz.hu & Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 12, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Integration for Szamlazz.hu & Gravity Forms Developer Profile

Viszt Péter

6 plugins · 16K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
478 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Szamlazz.hu & Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-szamlazz-hu-gravity-forms/assets/css/admin.css/wp-content/plugins/integration-for-szamlazz-hu-gravity-forms/assets/js/jquery-blockui/jquery.blockUI.js/wp-content/plugins/integration-for-szamlazz-hu-gravity-forms/assets/js/admin.js
Script Paths
/wp-content/plugins/integration-for-szamlazz-hu-gravity-forms/assets/js/jquery-blockui/jquery.blockUI.js/wp-content/plugins/integration-for-szamlazz-hu-gravity-forms/assets/js/admin.js
Version Parameters
/integration-for-szamlazz-hu-gravity-forms/assets/css/admin.css?ver=1.3/integration-for-szamlazz-hu-gravity-forms/assets/js/jquery-blockui/jquery.blockUI.js?ver=1.3/integration-for-szamlazz-hu-gravity-forms/assets/js/admin.js?ver=1.3

HTML / DOM Fingerprints

CSS Classes
gf_szamlazz_pro_version_activegf_szamlazz_pro_alertdelete-alertalert_red
HTML Comments
<!-- Workaround, so the description renders -->
Data Attributes
data-nonce
JS Globals
window.gf_szamlazz_admin_strings
REST Endpoints
/wp-json/gf_szamlazz/v1/settings/wp-json/gf_szamlazz/v1/license
FAQ

Frequently Asked Questions about Integration for Szamlazz.hu & Gravity Forms