Never Expire Submissions for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/never-expire-submissions-for-gravity-forms

Prevents automatic deletion of incomplete Gravity Forms submissions by extending the expiration time to 99,999 days.

0 active installs v2.0.5 PHP 7.4+ WP 6.0+ Updated Sep 16, 2025
data-protectionform-managementgravity-formsincompletesubmissions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Never Expire Submissions for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Never Expire Submissions for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The plugin "never-expire-submissions-for-gravity-forms" v2.0.5 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly those without authentication checks, significantly limits the potential attack surface. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and performing a high percentage of output escaping. The lack of file operations, external HTTP requests, and the absence of any identified dangerous functions further contribute to its secure design.

The vulnerability history also paints a positive picture, with no recorded CVEs, including no critical or high-severity vulnerabilities. This indicates a history of stable and secure development, with no known exploitable flaws to date. While the taint analysis found no issues, which is a positive sign, it's worth noting that the total flows analyzed was zero, which might mean there wasn't enough complex code to trigger taint analysis or that the analysis tool might have limitations.

Overall, the plugin appears to be well-developed from a security perspective, with minimal potential for vulnerabilities. The limited attack surface, secure coding practices for database interactions and output handling, and a clean vulnerability history are significant strengths. The primary area for potential concern, albeit minor and not directly evidenced as a flaw here, is the zero taint flows analyzed, suggesting the need to ensure thorough analysis is consistently applied to all code paths.

Key Concerns

  • No nonce checks found
  • Zero taint flows analyzed
Vulnerabilities
None known

Never Expire Submissions for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Never Expire Submissions for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
33 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped42 total outputs
Attack Surface

Never Expire Submissions for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menunever-expire-submissions-for-gravity-forms.php:560
actionadmin_enqueue_scriptsnever-expire-submissions-for-gravity-forms.php:561
actionplugins_loadednever-expire-submissions-for-gravity-forms.php:1073
actionadmin_noticesnever-expire-submissions-for-gravity-forms.php:1098
Maintenance & Trust

Never Expire Submissions for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version7.4
Downloads168

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Never Expire Submissions for Gravity Forms Developer Profile

Artur Nalobin

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Never Expire Submissions for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/never-expire-submissions-for-gravity-forms/assets/css/admin.css/wp-content/plugins/never-expire-submissions-for-gravity-forms/assets/js/admin.js
Script Paths
/wp-content/plugins/never-expire-submissions-for-gravity-forms/assets/js/admin.js
Version Parameters
never-expire-submissions-for-gravity-forms/assets/css/admin.css?ver=never-expire-submissions-for-gravity-forms/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf-never-expire-admin-page
Data Attributes
data-gf-never-expire-protection-statusdata-gf-never-expire-intervention-countdata-gf-never-expire-last-protection-timestampdata-gf-never-expire-last-protection-original-daysdata-gf-never-expire-last-protection-protected-daysdata-gf-never-expire-last-protection-status+1 more
JS Globals
GF_Never_Expire_Admin
FAQ

Frequently Asked Questions about Never Expire Submissions for Gravity Forms