PDF Importer for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/pdf-importer-for-gravity

Import a pdf, map it to a form and attaching to any email

20 active installs v1.3.81 PHP + WP 3.3+ Updated Mar 22, 2026
formspdfpdf-builderwpformwpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PDF Importer for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

PDF Importer for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'pdf-importer-for-gravity' v1.3.80 exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs and a high percentage of SQL queries using prepared statements, significant concerns arise from the static analysis. The presence of a dangerous function like `unserialize` without apparent sanitization, coupled with two identified flows with unsanitized paths, suggests a potential for remote code execution or arbitrary file read/write vulnerabilities. The absence of nonce checks on the single unprotected AJAX handler is a critical oversight, making it susceptible to CSRF attacks.

The plugin's reliance on the TCPDF library, while common, could also introduce risks if the library itself has unpatched vulnerabilities, although none are currently recorded for this plugin. The low percentage of properly escaped output is also concerning, potentially leading to XSS vulnerabilities. Overall, the plugin has some good security practices in place, such as prepared statements, but the identified vulnerabilities in handling user input and the lack of robust authentication on critical entry points present a notable risk that requires immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • Unsanitized path flows
  • Dangerous function: unserialize
  • Low proper output escaping percentage
  • Missing nonce checks on AJAX
Vulnerabilities
None known

PDF Importer for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PDF Importer for Gravity Forms Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

PDF Importer for Gravity Forms Code Analysis

Dangerous Functions
1
Raw SQL Queries
4
36 prepared
Unescaped Output
34
45 escaped
Nonce Checks
0
Capability Checks
1
File Operations
58
External Requests
1
Bundled Libraries
1

Dangerous Functions Found

unserialize$this->objects[$obj_id] = unserialize($obj);Lib\Cpdf\Cpdf.php:4663

Bundled Libraries

TCPDF

SQL Query Safety

90% prepared40 total queries

Output Escaping

57% escaped79 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
Export (ajax\ImporterManager.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

PDF Importer for Gravity Forms Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_pdf_importer_dont_show_again_noticeajax\ImporterManager.php:36
WordPress Hooks 8
actiongform_after_update_entrycore\Integration\Adapters\Gravity\Entry\GravityEntryProcessor.php:34
actiongform_entry_detail_sidebar_middlecore\Integration\Adapters\Gravity\Entry\GravityEntryProcessor.php:36
filterrnpdfimporter_get_loadercore\Loader.php:48
actionadmin_enqueue_scriptscore\PluginBase.php:124
actionadmin_menucore\PluginBase.php:125
actionadmin_initcore\PluginBase.php:126
actionadmin_print_stylescore\PluginBase.php:180
actionadmin_print_scriptscore\PluginBase.php:181
Maintenance & Trust

PDF Importer for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 22, 2026
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

PDF Importer for Gravity Forms Developer Profile

EDGARROJAS

19 plugins · 12K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
278 days
View full developer profile
Detection Fingerprints

How We Detect PDF Importer for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pdf-importer-for-gravity/core/css/Style.css/wp-content/plugins/pdf-importer-for-gravity/core/js/admin/pdf-importer-for-gravity-admin.js/wp-content/plugins/pdf-importer-for-gravity/core/js/pdf-importer-for-gravity.js
Script Paths
/wp-content/plugins/pdf-importer-for-gravity/core/js/admin/pdf-importer-for-gravity-admin.js/wp-content/plugins/pdf-importer-for-gravity/core/js/pdf-importer-for-gravity.js
Version Parameters
pdf-importer-for-gravity/core/css/Style.css?ver=pdf-importer-for-gravity/core/js/admin/pdf-importer-for-gravity-admin.js?ver=pdf-importer-for-gravity/core/js/pdf-importer-for-gravity.js?ver=

HTML / DOM Fingerprints

JS Globals
rednaopdfimpgravity_admin_paramsrednaopdfimpgravity_params
FAQ

Frequently Asked Questions about PDF Importer for Gravity Forms