PayPing GravityForms Security & Risk Analysis

wordpress.org/plugins/payping-gravityforms

افزونه درگاه پرداخت پی‌پینگ برای Gravity forms

20 active installs v2.5.2 PHP 7.2+ WP 6.2+ Updated Sep 14, 2025
gravity-formsiranpayping%da%af%d8%b1%d9%88%db%8c%d8%aa%db%8c-%d9%81%d8%b1%d9%85%d9%be%db%8c-%d9%be%db%8c%d9%86%da%af
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayPing GravityForms Safe to Use in 2026?

Generally Safe

Score 100/100

PayPing GravityForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The 'payping-gravityforms' plugin v2.5.2 exhibits a generally strong security posture based on the provided static analysis. A significant majority of SQL queries utilize prepared statements, and output escaping is robust, with 94% of outputs properly escaped. The absence of dangerous functions, file operations, and known vulnerabilities in its history are positive indicators. The limited attack surface, consisting of a single AJAX handler with no reported authentication checks, is a notable concern. While no taint analysis flagged critical or high-severity issues, and there are no recorded CVEs, the lack of capability checks on the single AJAX entry point presents a potential risk. This means that any authenticated user, regardless of their role, could potentially trigger this AJAX action, which could be exploited if the action itself is not inherently secure or if it performs sensitive operations.

The plugin benefits from good practices in SQL query handling and output sanitization, and its clean vulnerability history suggests a diligent development approach. However, the single unprotected AJAX handler stands out as a specific area for improvement. The absence of capability checks on this entry point means that privilege escalation is a theoretical risk if the AJAX handler's functionality is sensitive. Therefore, while the overall security is commendable, this specific oversight warrants attention to ensure all entry points are appropriately secured against unauthorized access.

Key Concerns

  • AJAX handler without auth checks
Vulnerabilities
None known

PayPing GravityForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PayPing GravityForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
77 prepared
Unescaped Output
22
356 escaped
Nonce Checks
9
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

99% prepared78 total queries

Output Escaping

94% escaped378 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
settings_page (payping.php:1021)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PayPing GravityForms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_payping_gravityforms_update_feed_activepayping.php:67
WordPress Hooks 18
actionadmin_enqueue_scriptspayping-gravityforms.php:17
actioninitpayping.php:9
actionadmin_noticespayping.php:27
actionadmin_noticespayping.php:33
filtergform_payment_statusespayping.php:37
filtermembers_get_capabilitiespayping.php:38
filtergform_tooltipspayping.php:42
filtergform_addon_navigationpayping.php:43
actiongform_entry_infopayping.php:44
actiongform_after_update_entrypayping.php:45
filtergform_form_settings_menupayping.php:48
actiongform_form_settings_page_paypingpayping.php:49
filtergform_disable_post_creationpayping.php:70
filtergform_is_delayed_pre_process_feedpayping.php:71
filtergform_confirmationpayping.php:73
actionwppayping.php:74
filtergform_logging_supportedpayping.php:77
filterpayping_gravityforms_payment_gatewayspayping.php:80
Maintenance & Trust

PayPing GravityForms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 14, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

PayPing GravityForms Developer Profile

PayPing

2 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayPing GravityForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payping-gravityforms/assets/js/scripts.js/wp-content/plugins/payping-gravityforms/assets/css/styles.css
Script Paths
assets/js/scripts.jsassets/js/shamsi_chart.jsassets/js/jalali-datepicker.js
Version Parameters
payping-gravityforms/assets/js/scripts.js?ver=payping-gravityforms/assets/css/styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapsubsubsub
Data Attributes
paypingGformData
JS Globals
paypingGformData
Shortcode Output
<ul class="subsubsub"><li><a class="href="?page=gravityforms_payping&view=stats&id=&tab=
FAQ

Frequently Asked Questions about PayPing GravityForms