
Never Expire Submissions for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/never-expire-submissions-for-gravity-formsPrevents automatic deletion of incomplete Gravity Forms submissions by extending the expiration time to 99,999 days.
Is Never Expire Submissions for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Never Expire Submissions for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "never-expire-submissions-for-gravity-forms" v2.0.5 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication checks, significantly limits the potential attack surface. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and performing a high percentage of output escaping. The lack of file operations, external HTTP requests, and the absence of any identified dangerous functions further contribute to its secure design.
The vulnerability history also paints a positive picture, with no recorded CVEs, including no critical or high-severity vulnerabilities. This indicates a history of stable and secure development, with no known exploitable flaws to date. While the taint analysis found no issues, which is a positive sign, it's worth noting that the total flows analyzed was zero, which might mean there wasn't enough complex code to trigger taint analysis or that the analysis tool might have limitations.
Overall, the plugin appears to be well-developed from a security perspective, with minimal potential for vulnerabilities. The limited attack surface, secure coding practices for database interactions and output handling, and a clean vulnerability history are significant strengths. The primary area for potential concern, albeit minor and not directly evidenced as a flaw here, is the zero taint flows analyzed, suggesting the need to ensure thorough analysis is consistently applied to all code paths.
Key Concerns
- No nonce checks found
- Zero taint flows analyzed
Never Expire Submissions for Gravity Forms Security Vulnerabilities
Never Expire Submissions for Gravity Forms Code Analysis
Output Escaping
Never Expire Submissions for Gravity Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Never Expire Submissions for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Never Expire Submissions for Gravity Forms Alternatives
Spark GF Failed Submissions
spark-gf-failed-submissions
Track failed form submissions and get notified when they reach a customisable threshold. Requires Gravity Forms.
Gravity Forms Data Purge
gf-data-purge
Simple plugin to purge data from Gravity Forms Entries that are older that a certain number of days.
Notification Review for Gravity Forms
notification-review-for-gravity-forms
Adds a "Notification Review" submenu item under Forms to display a table of all Gravity Forms notifications on your website.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Never Expire Submissions for Gravity Forms Developer Profile
2 plugins · 0 total installs
How We Detect Never Expire Submissions for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/never-expire-submissions-for-gravity-forms/assets/css/admin.css/wp-content/plugins/never-expire-submissions-for-gravity-forms/assets/js/admin.js/wp-content/plugins/never-expire-submissions-for-gravity-forms/assets/js/admin.jsnever-expire-submissions-for-gravity-forms/assets/css/admin.css?ver=never-expire-submissions-for-gravity-forms/assets/js/admin.js?ver=HTML / DOM Fingerprints
gf-never-expire-admin-pagedata-gf-never-expire-protection-statusdata-gf-never-expire-intervention-countdata-gf-never-expire-last-protection-timestampdata-gf-never-expire-last-protection-original-daysdata-gf-never-expire-last-protection-protected-daysdata-gf-never-expire-last-protection-status+1 moreGF_Never_Expire_Admin