Paystack Add-On for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/paystack-add-on-for-gravity-forms

The Paystack Addon for Gravity Forms allows you to quickly and easily implement credit card payments with WordPress. With the Paystack Add-On you can …

400 active installs v2.0.6 PHP + WP 5.1+ Updated Jul 23, 2025
gravityformspaymentssubscriptions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paystack Add-On for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Paystack Add-On for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "paystack-add-on-for-gravity-forms" v2.0.6 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, SQL queries using prepared statements, and a lack of critical or high severity taint flows are positive indicators. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of responsible development and maintenance. The presence of file operations and external HTTP requests, while not inherently risky, are areas that should always be scrutinized for proper sanitization and validation, especially in production environments.

However, there are some areas that raise minor concerns. The 56% output escaping rate, while not alarmingly low, indicates that a portion of output is not being properly sanitized, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is passed through these unescaped outputs. The lack of nonce checks on any potential entry points, coupled with only one capability check, suggests that authentication and authorization mechanisms might be less robust than ideal, potentially leaving some actions vulnerable to unauthorized execution if an attack surface were to be discovered or created.

In conclusion, the plugin appears to be built with a good foundation of security practices, particularly concerning data handling and SQL injection prevention. The lack of known vulnerabilities is a significant strength. The primary areas for improvement lie in ensuring all output is properly escaped and strengthening authentication/authorization checks, especially if new entry points are introduced in future versions. Overall, the immediate risk appears low, but attention to the identified areas of concern is recommended for continued security.

Key Concerns

  • Partial output escaping
  • No nonce checks on entry points
Vulnerabilities
None known

Paystack Add-On for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Paystack Add-On for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
4
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

56% escaped9 total outputs
Attack Surface

Paystack Add-On for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwpclass-gf-paystack.php:237
filtergform_currenciesclass-gf-paystack.php:246
actiongform_loadedpaystack.php:36
Maintenance & Trust

Paystack Add-On for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 23, 2025
PHP min version
Downloads8K

Community Trust

Rating60/100
Number of ratings2
Active installs400
Developer Profile

Paystack Add-On for Gravity Forms Developer Profile

paystack

5 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paystack Add-On for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paystack-add-on-for-gravity-forms/assets/css/admin.css/wp-content/plugins/paystack-add-on-for-gravity-forms/assets/js/admin.js/wp-content/plugins/paystack-add-on-for-gravity-forms/assets/js/frontend.js
Script Paths
/wp-content/plugins/paystack-add-on-for-gravity-forms/assets/js/admin.js/wp-content/plugins/paystack-add-on-for-gravity-forms/assets/js/frontend.js
Version Parameters
paystack-add-on-for-gravity-forms/assets/css/admin.css?ver=paystack-add-on-for-gravity-forms/assets/js/admin.js?ver=paystack-add-on-for-gravity-forms/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
gf_paystack_settings
HTML Comments
Paystack Add-On for Gravity FormsCopyright 2020 PaystackThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,+26 more
Data Attributes
data-paystack-settings
JS Globals
gf_paystack_admin_params
FAQ

Frequently Asked Questions about Paystack Add-On for Gravity Forms