Migrate Wufoo To Gravity Forms Security & Risk Analysis

wordpress.org/plugins/migrate-wufoo-to-gravity-forms

"Wufoo to Gravity Forms Importer" imports form entries, comments and attachments from your Wufoo account to Gravity Forms.

10 active installs v1.0 PHP + WP 3.0+ Updated Unknown
gravity-formsgravityformswordpresswufoo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Migrate Wufoo To Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Migrate Wufoo To Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'migrate-wufoo-to-gravity-forms' version 1.0 exhibits several significant security concerns that require immediate attention. While the plugin has no recorded vulnerability history, suggesting a lack of past exploitable flaws, its static analysis reveals a precarious security posture. A substantial attack surface is exposed through 9 AJAX handlers, all of which lack authentication checks, creating a wide opening for unauthorized actions. Compounding this, the taint analysis indicates 2 high-severity flows with unsanitized paths, suggesting potential for injection attacks or data manipulation through these entry points. Furthermore, the complete absence of output escaping for any of the analyzed outputs is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities.

Key Concerns

  • AJAX handlers without authentication checks
  • High severity taint flows with unsanitized paths
  • No output escaping
  • No nonce checks on AJAX handlers
  • Capability checks missing on AJAX handlers
Vulnerabilities
None known

Migrate Wufoo To Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Migrate Wufoo To Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
7 prepared
Unescaped Output
19
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

58% prepared12 total queries

Output Escaping

0% escaped19 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
comment_import (rtWufoo.php:150)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
9 unprotected

Migrate Wufoo To Gravity Forms Attack Surface

Entry Points9
Unprotected9

AJAX Handlers 9

authwp_ajax_rt_wufoo_api_formrtWufoo.php:40
authwp_ajax_rt_wufoo_form_select_uirtWufoo.php:43
authwp_ajax_rt_wufoo_comment_count_ajaxrtWufoo.php:46
authwp_ajax_rt_wufoo_comment_importrtWufoo.php:49
authwp_ajax_rt_wufoo_comment_nextrtWufoo.php:53
authwp_ajax_rt_wufoo_map_usersrtWufoo.php:56
authwp_ajax_rt_wufoo_form_fields_maprtWufoo.php:59
authwp_ajax_rt_wufoo_field_mapping_formrtWufoo.php:62
authwp_ajax_rt_wufoo_import_entriesrtWufoo.php:65
WordPress Hooks 1
actionadmin_menurtWufoo.php:38
Maintenance & Trust

Migrate Wufoo To Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Migrate Wufoo To Gravity Forms Developer Profile

rtCamp

19 plugins · 119K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
883 days
View full developer profile
Detection Fingerprints

How We Detect Migrate Wufoo To Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/migrate-wufoo-to-gravity-forms/rtWufoo.css/wp-content/plugins/migrate-wufoo-to-gravity-forms/rtWufoo.js
Script Paths
/wp-content/plugins/migrate-wufoo-to-gravity-forms/rtWufoo.js
Version Parameters
migrate-wufoo-to-gravity-forms/rtWufoo.css?ver=migrate-wufoo-to-gravity-forms/rtWufoo.js?ver=

HTML / DOM Fingerprints

CSS Classes
rt_wufoo_stepsrt-wufoo-step-apirt-wufoo-step-formrt-wufoo-step-usersrt-wufoo-step-fieldsrt-wufoo-step-importrt_wufoo_wizardrt_wufoo_error
Data Attributes
id="rt_wufoo_wizard"id="rt_wufoo_error"class="rt_wufoo_steps"id="rt-wufoo-step-api"id="rt-wufoo-step-form"id="rt-wufoo-step-users"+2 more
JS Globals
rt_wufoo_gravity_subdomainrt_wufoo_gravity_api_key
REST Endpoints
/wp-json/rt_wufoo_api_form/wp-json/rt_wufoo_form_select_ui/wp-json/rt_wufoo_comment_count_ajax/wp-json/rt_wufoo_comment_import/wp-json/rt_wufoo_comment_next/wp-json/rt_wufoo_map_users/wp-json/rt_wufoo_form_fields_map/wp-json/rt_wufoo_field_mapping_form/wp-json/rt_wufoo_import_entries
FAQ

Frequently Asked Questions about Migrate Wufoo To Gravity Forms