
PDF Builder for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/pdf-builder-for-gravityThe first and only PDF drag and drop builder for Gravity Forms.
Is PDF Builder for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100PDF Builder for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pdf-builder-for-gravity" plugin version 1.2.141 exhibits a concerning security posture primarily due to a significant number of unprotected entry points. The static analysis reveals 4 AJAX handlers, all of which lack authentication checks. This creates a broad attack surface where any unauthenticated user could potentially interact with sensitive plugin functionalities. Furthermore, the taint analysis indicates 2 high-severity flows with unsanitized paths, suggesting a risk of data manipulation or injection if these flows are reachable without proper sanitization.
Despite these concerns, the plugin demonstrates good practices in other areas. The vast majority of SQL queries utilize prepared statements, a strong defense against SQL injection. The plugin also implements a reasonable number of capability checks and a nonce check, indicating an awareness of common security measures. The absence of known CVEs and vulnerabilities in its history is a positive sign, suggesting the developers have addressed past issues or that the plugin has not been a frequent target. However, the current analysis highlights immediate risks that outweigh the positive historical trends, particularly the unprotected AJAX endpoints and high-severity taint flows.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows with unsanitized paths
- Low output escaping rate
- Bundled outdated TCPDF library
PDF Builder for Gravity Forms Security Vulnerabilities
PDF Builder for Gravity Forms Release Timeline
PDF Builder for Gravity Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PDF Builder for Gravity Forms Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
PDF Builder for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
PDF Builder for Gravity Forms Alternatives
PDF Builder for WPForms
pdf-builder-for-wpforms
The first and only PDF drag and drop builder for WPForms.
PDF Importer for WPForms
pdf-importer-for-wpform
Import a pdf, map it to a form and attaching to any email
PDF Importer for Gravity Forms
pdf-importer-for-gravity
Import a pdf, map it to a form and attaching to any email
PDF Importer for Ninja Forms
pdf-importer-for-ninjaforms-pro
Import a pdf, map it to a form and attaching to any email
PDF for WPForms + Drag and Drop Template Builder
pdf-for-wpforms
The plugin helps you create PDF for WPForms you can builder PDF template
PDF Builder for Gravity Forms Developer Profile
19 plugins · 12K total installs
How We Detect PDF Builder for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-builder-for-gravity/js/dist/Designer_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/EntryList_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/EntryView_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/PDFList_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/TemplateList_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/Settings_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/DeactivationDialog_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/Designer_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/EntryList_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/EntryView_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/PDFList_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/TemplateList_bundle.js/wp-content/plugins/pdf-builder-for-gravity/js/dist/Settings_bundle.js+1 moreHTML / DOM Fingerprints
pdfbuilder-designerpdfbuilder-entry-listpdfbuilder-entry-viewpdfbuilder-pdf-listpdfbuilder-template-listpdfbuilder-settings<!--Looks like you already have a version of the plugin installed (perhaps the free version)? please deactivate/delete it before activating this version -->data-rednao-pdf-builder-item-iddata-rednao-pdf-builder-authorRednaoPDFBuilderRednaoPDFBuilderDesignerRednaoPDFBuilderTemplateListRednaoPDFBuilderEntryListRednaoPDFBuilderEntryViewRednaoPDFBuilderSettings/wp-json/rednaoformpdfbuilder/v1/designer/wp-json/rednaoformpdfbuilder/v1/template-list/wp-json/rednaoformpdfbuilder/v1/pdf-utils