Gravity Forms payment plugin – Novalnet AG Security & Risk Analysis

wordpress.org/plugins/novalnet-payment-add-on-for-gravity-forms

Novalnet payment addon provides all popular online payment methods for your Gravity Forms webshop.

10 active installs v3.2.0 PHP + WP 5.0+ Updated Sep 19, 2025
credit-cardsnovalnet-paymentpayment-gatewaypayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms payment plugin – Novalnet AG Safe to Use in 2026?

Generally Safe

Score 100/100

Gravity Forms payment plugin – Novalnet AG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "novalnet-payment-add-on-for-gravity-forms" plugin v3.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by largely utilizing prepared statements for its SQL queries and performing output escaping on most of its outputs. The absence of known vulnerabilities and critical taint flows is also a strong indicator of a generally secure development process. The plugin also doesn't bundle any potentially outdated libraries.

However, significant security concerns arise from the identified attack surface. With two AJAX handlers, both lacking authentication checks, there's a clear vulnerability that could allow unauthorized users to trigger plugin functionality. While there are nonce checks present, their effectiveness is diminished without proper authorization verification on these entry points. The plugin also performs one file operation and one external HTTP request, which, while not inherently insecure, are areas that warrant careful scrutiny for potential exploitation if combined with other vulnerabilities.

Overall, the plugin's lack of historical vulnerabilities is encouraging, suggesting that past development has been responsible. However, the presence of unprotected AJAX endpoints represents a critical weakness that needs immediate attention. The plugin's strengths lie in its SQL and output sanitization, but its attack surface management is a significant area for improvement. The absence of capability checks on AJAX handlers is a notable oversight.

Key Concerns

  • AJAX handlers without authorization checks
  • AJAX entry points without auth checks
  • Lack of capability checks on entry points
Vulnerabilities
None known

Gravity Forms payment plugin – Novalnet AG Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gravity Forms payment plugin – Novalnet AG Release Timeline

v3.1.0
v3.0.0
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms payment plugin – Novalnet AG Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
5
29 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

85% escaped34 total outputs
Attack Surface
2 unprotected

Gravity Forms payment plugin – Novalnet AG Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_send_auto_config_callclass-gf-novalnet.php:174
authwp_ajax_config_novalnet_hook_urlclass-gf-novalnet.php:176
WordPress Hooks 16
actionwpclass-gf-novalnet.php:141
actionparse_requestclass-gf-novalnet.php:142
actionadmin_initclass-gf-novalnet.php:168
filtergform_form_tagclass-gf-novalnet.php:172
filtergform_replace_merge_tagsclass-gf-novalnet.php:178
filtergform_merge_tag_dataclass-gf-novalnet.php:180
actionadmin_enqueue_scriptsclass-gf-novalnet.php:182
filterscript_loader_tagclass-gf-novalnet.php:184
filtergform_disable_notificationclass-gf-novalnet.php:186
filtergform_custom_merge_tagsclass-gf-novalnet.php:188
filternovalnet_store_instalment_dataclass-gf-novalnet.php:190
filternovalnet_store_instalment_data_webhookclass-gf-novalnet.php:192
filtergform_entry_detail_meta_boxesclass-gf-novalnet.php:194
actiongform_payment_detailsclass-gf-novalnet.php:196
actiongform_payment_statusesclass-gf-novalnet.php:198
actiongform_loadednovalnet-gravity-forms.php:61
Maintenance & Trust

Gravity Forms payment plugin – Novalnet AG Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 19, 2025
PHP min version
Downloads992

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Gravity Forms payment plugin – Novalnet AG Developer Profile

Novalnet

4 plugins · 1K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms payment plugin – Novalnet AG

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/js/novalnet-admin.min.js/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/includes/class-gf-novalnet-setup.php/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/includes/class-gf-novalnet-helper.php/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/class-gf-novalnet.php/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/novalnet-gravity-forms.php
Script Paths
js/novalnet-admin.min.js
Version Parameters
novalnet-payment-add-on-for-gravity-forms/novalnet-gravity-forms.php?ver=novalnet-payment-add-on-for-gravity-forms/js/novalnet-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
gaddon-setting-row-gform_setting_
Data Attributes
data-novalnet-configuration
JS Globals
gf_novalnet_admin_strings
FAQ

Frequently Asked Questions about Gravity Forms payment plugin – Novalnet AG