OptionTree Extension: Gravity Forms Security & Risk Analysis

wordpress.org/plugins/optiontree-extension-gravity-forms

Adds Option Tree fields for linking Gravity Forms to Option Tree, allowing you to select a specific form for an option.

10 active installs v0.2.1 PHP + WP 3.0+ Updated Mar 13, 2014
gravity-formsgravityformsoption-treeoptionsoptiontree
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is OptionTree Extension: Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

OptionTree Extension: Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The static analysis of optiontree-extension-gravity-forms v0.2.1 reveals a plugin with a seemingly minimal attack surface, as indicated by zero identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is positive. The use of prepared statements for SQL queries is a strong security practice. However, a significant concern arises from the 38% of outputs that are not properly escaped, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data reaches these unescaped outputs. The lack of nonce checks and capability checks across all identified entry points is also a notable weakness, although the current zero entry points mitigate immediate risk from this specific omission. The vulnerability history shows no known CVEs, which is a good sign, but it's important to note that this could be due to the plugin's age or lack of extensive security auditing rather than inherent security. Overall, while the plugin demonstrates good practices in areas like SQL handling and avoids common pitfalls like bundled libraries, the unescaped output and missing authentication checks on potential (though currently absent) entry points represent areas of concern that require attention.

Key Concerns

  • Unescaped output found
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

OptionTree Extension: Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

OptionTree Extension: Gravity Forms Release Timeline

v0.2.1Current
v0.2
v0.1
Code Analysis
Analyzed Apr 16, 2026

OptionTree Extension: Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped13 total outputs
Attack Surface

OptionTree Extension: Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitoption-tree-gravityforms.php:25
filterot_option_types_arrayoption-tree-gravityforms.php:26
Maintenance & Trust

OptionTree Extension: Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 13, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

OptionTree Extension: Gravity Forms Developer Profile

Jesper van Engelen

8 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OptionTree Extension: Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
type-gravityforms-form
FAQ

Frequently Asked Questions about OptionTree Extension: Gravity Forms