Invitation Codes: Gravityforms Add-on Security & Risk Analysis

wordpress.org/plugins/invitation-codes-gravityforms-add-on

A GravityForms addon to enable users to use custom invitation codes in combination with GravityForms.

20 active installs v1.5 PHP 7.4+ WP 5.5+ Updated Sep 21, 2025
gravity-formgravityformsinvitation-codesinvitationcodes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Invitation Codes: Gravityforms Add-on Safe to Use in 2026?

Generally Safe

Score 100/100

Invitation Codes: Gravityforms Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "invitation-codes-gravityforms-add-on" plugin version 1.5 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication or proper permission checks. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests. All SQL queries are handled using prepared statements, and all output is properly escaped, eliminating common vulnerabilities like SQL injection and cross-site scripting (XSS). The absence of taint analysis findings further reinforces this positive assessment, indicating no detectable unsanitized data flows.

The plugin's vulnerability history is also exceptionally clean, with zero known CVEs recorded. This lack of past vulnerabilities suggests a commitment to secure coding practices by the developers. The combination of a minimal attack surface, robust code sanitization and escaping, and a clean vulnerability record indicates a very low risk profile for this plugin. While the absence of nonce checks is noted, given the lack of exposed entry points, this does not currently present a practical risk.

In conclusion, this plugin appears to be well-secured. The developers have implemented good security practices by minimizing the attack surface and ensuring that any potential data handling is done safely. The clean vulnerability history is a significant strength. The only minor point of concern is the absence of nonce checks, but this is mitigated by the lack of accessible entry points.

Key Concerns

  • Missing nonce checks on entry points
Vulnerabilities
None known

Invitation Codes: Gravityforms Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Invitation Codes: Gravityforms Add-on Release Timeline

v1.5Current
v1.4
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Invitation Codes: Gravityforms Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Attack Surface

Invitation Codes: Gravityforms Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergform_tooltipsclass-gf-invitation-code.php:67
actiongform_field_standard_settingsclass-gf-invitation-code.php:68
actiongform_loadedgf-invitation-code.php:24
Maintenance & Trust

Invitation Codes: Gravityforms Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 21, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Invitation Codes: Gravityforms Add-on Developer Profile

Peshmerge Morad

4 plugins · 120 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Invitation Codes: Gravityforms Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/invitation-codes-gravityforms-add-on/assets/css/gf-invitation-code.css/wp-content/plugins/invitation-codes-gravityforms-add-on/assets/js/gf-invitation-code.js
Script Paths
/wp-content/plugins/invitation-codes-gravityforms-add-on/assets/js/gf-invitation-code.js
Version Parameters
invitation-codes-gravityforms-add-on/assets/css/gf-invitation-code.css?ver=invitation-codes-gravityforms-add-on/assets/js/gf-invitation-code.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf-invitation-code-section
FAQ

Frequently Asked Questions about Invitation Codes: Gravityforms Add-on