
Marketing 360® Payments for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/marketing-360-payments-for-gravity-formsCreate online payment forms with Gravity Forms and Marketing 360®, the #1 Marketing Platform® for Small Business.
Is Marketing 360® Payments for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Marketing 360® Payments for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "marketing-360-payments-for-gravity-forms" v1.0.7 reveals a generally positive security posture with no recorded CVEs and a commitment to secure SQL practices. The plugin uses prepared statements exclusively for its SQL queries, which is a significant strength. Furthermore, the vast majority of its output is properly escaped, mitigating common cross-site scripting risks. The limited attack surface, with zero identified AJAX handlers, REST API routes, shortcodes, or cron events, suggests a focused functionality that doesn't expose numerous entry points. The absence of taint analysis findings also indicates no immediately obvious code flows leading to exploitable vulnerabilities.
However, several concerns warrant attention. The presence of two instances of the `unserialize` function is a significant risk. If the data being unserialized is not strictly controlled and validated, it can lead to object injection vulnerabilities. The complete lack of nonce checks and capability checks across all entry points is also a serious oversight. This means that any functionality, if discoverable, could potentially be triggered by unauthenticated or low-privileged users, leading to unauthorized actions. The plugin also makes a substantial number of external HTTP requests (11), which, without proper validation of the data being sent or received, could expose the site to various risks, including data leakage or manipulation by compromised external services.
Given the complete absence of historical vulnerabilities, the plugin might have a good development team or simply hasn't been a target. However, the static analysis highlights potential weaknesses that could be exploited. The strengths lie in its SQL practices and output escaping, but the risks associated with `unserialize` and the absence of authentication/authorization checks on any potential entry points are considerable.
Key Concerns
- Dangerous function unserialize present
- No nonce checks found
- No capability checks found
- 11 external HTTP requests
- 11% of outputs unescaped
Marketing 360® Payments for Gravity Forms Security Vulnerabilities
Marketing 360® Payments for Gravity Forms Release Timeline
Marketing 360® Payments for Gravity Forms Code Analysis
Dangerous Functions Found
Output Escaping
Marketing 360® Payments for Gravity Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Marketing 360® Payments for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Marketing 360® Payments for Gravity Forms Alternatives
Gravity Forms Eway
gravityforms-eway
Easily create online payment forms with Gravity Forms and Eway.
GF ACH Field Type
gf-ach-field
This plugin enables you to add ACH field type to Gravity Forms.
Charitable – Instamojo Payment Gateway
integrate-charitable-instamojo
Collect donations in INR via Debit Cards, Credit Cards, Net Banking, UPI, Wallets, EMI, NEFT, IMPS by integrating Instamojo Indian Payment Gateway.
LSX PayFast Gateway for Give
lsx-give-payfast-gateway
PayFast payment gateway for Give.
SmartPay
smartpay
Sell digital downloads and accept payments including donations easily with Stripe, PayPal, Paddle etc. - simple, fast, and secure.
Marketing 360® Payments for Gravity Forms Developer Profile
2 plugins · 40 total installs
How We Detect Marketing 360® Payments for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/marketing-360-payments-for-gravity-forms/assets/css/gf_m360_styles.css/wp-content/plugins/marketing-360-payments-for-gravity-forms/assets/js/gf_m360_scripts.js/wp-content/plugins/marketing-360-payments-for-gravity-forms/assets/js/gf_m360_scripts.jsmarketing-360-payments-for-gravity-forms/assets/css/gf_m360_styles.css?ver=marketing-360-payments-for-gravity-forms/assets/js/gf_m360_scripts.js?ver=HTML / DOM Fingerprints
gf_m360_login_containergf_m360_login_sectiongf_m360_login_buttongf_m360_signed_out_messagedata-plugin-pathgf_m360_ajaxurl/wp-json/gf_marketing_360_payments/v1/sign_in