
MaxiCharts Gravity Forms Source add-on Security & Risk Analysis
wordpress.org/plugins/maxicharts-gravity-forms-source-add-onExtends MaxiCharts to chart Gravity Forms data.
Is MaxiCharts Gravity Forms Source add-on Safe to Use in 2026?
Generally Safe
Score 85/100MaxiCharts Gravity Forms Source add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The maxicharts-gravity-forms-source-add-on plugin v1.7.10 presents a generally good security posture with several strengths. The absence of known CVEs and unpatched vulnerabilities is a significant positive indicator. Static analysis reveals no raw SQL queries, all output is properly escaped, and there are no file operations or external HTTP requests, all of which are excellent security practices. The limited attack surface of two shortcodes with no identified unprotected entry points is also reassuring.
However, there are a couple of concerning signals. The presence of the `unserialize` function, even if not directly exploitable in this version based on the provided data, always carries inherent risks. It's crucial to ensure that any data being unserialized is strictly controlled and validated to prevent potential remote code execution vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks across all entry points is a significant weakness. While the static analysis indicates no unprotected entry points from an authentication perspective currently, this leaves the plugin vulnerable to cross-site request forgery (CSRF) attacks should any of the shortcodes be susceptible to manipulation by malicious actors. The lack of any taint analysis flows is also noteworthy, suggesting either a very clean codebase or that the analysis might not have covered all potential paths.
In conclusion, while the plugin benefits from a clean vulnerability history and strong adherence to output escaping and prepared statements, the reliance on `unserialize` without explicit context and, more importantly, the complete lack of nonce and capability checks on its entry points represent significant security concerns that should be addressed. The absence of these standard WordPress security mechanisms creates a potential attack vector that is not currently mitigated.
Key Concerns
- Dangerous function used (unserialize)
- Missing nonce checks on entry points
- Missing capability checks on entry points
MaxiCharts Gravity Forms Source add-on Security Vulnerabilities
MaxiCharts Gravity Forms Source add-on Code Analysis
Dangerous Functions Found
Output Escaping
MaxiCharts Gravity Forms Source add-on Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
MaxiCharts Gravity Forms Source add-on Maintenance & Trust
Maintenance Signals
Community Trust
MaxiCharts Gravity Forms Source add-on Alternatives
MaxiCharts
maxicharts
Create beautiful HTML5 charts from Gravity Forms submission data with a simple shortcode. You can also visualise CSV files as graphs.
Gravity Forms Light Blue API Add-On
gravity-forms-light-blue-api-add-on
Send information directly from your Gravity Forms forms to your Light Blue account.
FortressDB
fortressdb
High-speed, secure database plugin for WordPress form data
Embed charts graphs tables and forms with Vixo
vixo-embeddable-tables-charts-and-spreadsheets
Lets you embed graphs and graphs, tables, spreadsheets, forms and quotation engines from the Vixo online spreadsheet.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
MaxiCharts Gravity Forms Source add-on Developer Profile
14 plugins · 800 total installs
How We Detect MaxiCharts Gravity Forms Source add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/maxicharts-gravity-forms-source-add-on/mcharts_gf_source_add_on.phpHTML / DOM Fingerprints
[gfchartsreports][gfentryfieldvalue]