
Gravity Forms payment plugin – Novalnet AG Security & Risk Analysis
wordpress.org/plugins/novalnet-payment-add-on-for-gravity-formsNovalnet payment addon provides all popular online payment methods for your Gravity Forms webshop.
Is Gravity Forms payment plugin – Novalnet AG Safe to Use in 2026?
Generally Safe
Score 100/100Gravity Forms payment plugin – Novalnet AG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "novalnet-payment-add-on-for-gravity-forms" plugin v3.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by largely utilizing prepared statements for its SQL queries and performing output escaping on most of its outputs. The absence of known vulnerabilities and critical taint flows is also a strong indicator of a generally secure development process. The plugin also doesn't bundle any potentially outdated libraries.
However, significant security concerns arise from the identified attack surface. With two AJAX handlers, both lacking authentication checks, there's a clear vulnerability that could allow unauthorized users to trigger plugin functionality. While there are nonce checks present, their effectiveness is diminished without proper authorization verification on these entry points. The plugin also performs one file operation and one external HTTP request, which, while not inherently insecure, are areas that warrant careful scrutiny for potential exploitation if combined with other vulnerabilities.
Overall, the plugin's lack of historical vulnerabilities is encouraging, suggesting that past development has been responsible. However, the presence of unprotected AJAX endpoints represents a critical weakness that needs immediate attention. The plugin's strengths lie in its SQL and output sanitization, but its attack surface management is a significant area for improvement. The absence of capability checks on AJAX handlers is a notable oversight.
Key Concerns
- AJAX handlers without authorization checks
- AJAX entry points without auth checks
- Lack of capability checks on entry points
Gravity Forms payment plugin – Novalnet AG Security Vulnerabilities
Gravity Forms payment plugin – Novalnet AG Release Timeline
Gravity Forms payment plugin – Novalnet AG Code Analysis
SQL Query Safety
Output Escaping
Gravity Forms payment plugin – Novalnet AG Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Gravity Forms payment plugin – Novalnet AG Maintenance & Trust
Maintenance Signals
Community Trust
Gravity Forms payment plugin – Novalnet AG Alternatives
Novalnet Payment Gateway for WooCommerce
woocommerce-novalnet-gateway
Novalnet payment plugin provides all popular online payment methods for your WooCommerce webshop.
MemberPress payment addon – Novalnet AG
novalnet-payment-addon-memberpress
Novalnet payment addon provides all popular online payment methods for your MemberPress webshop.
Pay Advantage
pay-advantage
Instantly accept Visa, Mastercard and American Express from your site with fast settlement to any Australian bank account.
Charge Anywhere Payment Gateway for WooCommerce
charge-anywhere-payment-gateway-for-woocommerce
Charge Anywhere payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Easy Digital Downloads payment plugin – Novalnet AG
easy-digital-downloads-payment-gateway-by-novalnet
Novalnet payment plugin provides all popular online payment methods for your Easy Digital Downloads webshop.
Gravity Forms payment plugin – Novalnet AG Developer Profile
4 plugins · 1K total installs
How We Detect Gravity Forms payment plugin – Novalnet AG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/js/novalnet-admin.min.js/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/includes/class-gf-novalnet-setup.php/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/includes/class-gf-novalnet-helper.php/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/class-gf-novalnet.php/wp-content/plugins/novalnet-payment-add-on-for-gravity-forms/novalnet-gravity-forms.phpjs/novalnet-admin.min.jsnovalnet-payment-add-on-for-gravity-forms/novalnet-gravity-forms.php?ver=novalnet-payment-add-on-for-gravity-forms/js/novalnet-admin.min.js?ver=HTML / DOM Fingerprints
gaddon-setting-row-gform_setting_data-novalnet-configurationgf_novalnet_admin_strings