
Live Summary for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/live-summary-for-gravity-formsThis simple and handy plugin will add a live summary next to any gravity form. No coding required.
Is Live Summary for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 92/100Live Summary for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'live-summary-for-gravity-forms' plugin exhibits a concerning security posture primarily due to its large attack surface without adequate authentication. All six identified AJAX handlers lack authentication checks, creating a significant risk for unauthorized actions. While the plugin avoids dangerous functions and uses prepared statements for SQL queries, this strength is overshadowed by the critical lack of authorization. The taint analysis, although limited, did not reveal unsanitized paths with high severity, which is a positive sign. However, the static analysis highlights that only 41% of output is properly escaped, suggesting potential cross-site scripting (XSS) vulnerabilities in certain scenarios. The plugin's vulnerability history is clean, with no known CVEs, which indicates a historical tendency towards secure development or simply a lack of past exploitation. Despite the absence of known vulnerabilities and the use of prepared SQL statements, the unprotected AJAX endpoints represent a substantial and direct security risk that needs immediate attention. The overall assessment is that while the plugin has some good practices, the unprotected attack surface is a critical weakness that demands mitigation.
Key Concerns
- Multiple AJAX handlers lack authentication
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
Live Summary for Gravity Forms Security Vulnerabilities
Live Summary for Gravity Forms Code Analysis
Output Escaping
Data Flow Analysis
Live Summary for Gravity Forms Attack Surface
AJAX Handlers 6
WordPress Hooks 13
Maintenance & Trust
Live Summary for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Live Summary for Gravity Forms Alternatives
GravityExport Lite for Gravity Forms
gf-entries-in-excel
Export all Gravity Forms entries to Excel (.xlsx) or CSV via a download button or a secret shareable URL.
Multiple Columns for Gravity Forms
gf-form-multicolumn
Introduces new form elements into Gravity Forms which allow for simple column creation.
Surbma | Divi & Gravity Forms
surbma-divi-gravity-forms
Responsive Divi form styles for Gravity Forms.
Fresh Forms for Gravity
fresh-forms-for-gravity
Prevent supported caching and JS optimization plugins breaking Gravity Forms.
Divi Gravity Forms (WP Tools)
wp-tools-gravity-forms-divi-module
Divi 4 & 5 module to integrate Gravity Forms. Create custom-designed forms for your website using extensive style customization options, no coding …
Live Summary for Gravity Forms Developer Profile
1 plugin · 2K total installs
How We Detect Live Summary for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-summary-for-gravity-forms/js/summary-change.js/wp-content/plugins/live-summary-for-gravity-forms/images/live-summary-upgrade-banner.jpg/wp-content/plugins/live-summary-for-gravity-forms/js/summary-change.jslive-summary-for-gravity-forms/style.css?ver=live-summary-for-gravity-forms/js/summary-change.js?ver=HTML / DOM Fingerprints
gotrgf-summary-containergotrgf-summary-headinggotrgf-summary-itemgotrgf-summary-quantitygotrgf-summary-pricegotrgf-summary-total<!-- Temporary Function to migrate settings --><!-- //add a buy link on the plugins page if the pro version is not installed --><!-- add tasks or filters here that you want to perform during the class constructor - before WordPress has been completely initialized --><!-- add tasks or filters here that you want to perform both in the backend and frontend and for ajax requests -->+3 moredata-form-iddata-target-fielddata-field-typedata-field-iddata-gf-summary-fieldfrontendajax/wp-json/gotrgf/v1/retrieve-fields/wp-json/gotrgf/v1/retrieve-field-object/wp-json/gotrgf/v1/format-money