
PDF Importer for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/pdf-importer-for-gravityImport a pdf, map it to a form and attaching to any email
Is PDF Importer for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100PDF Importer for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'pdf-importer-for-gravity' v1.3.80 exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs and a high percentage of SQL queries using prepared statements, significant concerns arise from the static analysis. The presence of a dangerous function like `unserialize` without apparent sanitization, coupled with two identified flows with unsanitized paths, suggests a potential for remote code execution or arbitrary file read/write vulnerabilities. The absence of nonce checks on the single unprotected AJAX handler is a critical oversight, making it susceptible to CSRF attacks.
The plugin's reliance on the TCPDF library, while common, could also introduce risks if the library itself has unpatched vulnerabilities, although none are currently recorded for this plugin. The low percentage of properly escaped output is also concerning, potentially leading to XSS vulnerabilities. Overall, the plugin has some good security practices in place, such as prepared statements, but the identified vulnerabilities in handling user input and the lack of robust authentication on critical entry points present a notable risk that requires immediate attention.
Key Concerns
- Unprotected AJAX handler
- Unsanitized path flows
- Dangerous function: unserialize
- Low proper output escaping percentage
- Missing nonce checks on AJAX
PDF Importer for Gravity Forms Security Vulnerabilities
PDF Importer for Gravity Forms Release Timeline
PDF Importer for Gravity Forms Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PDF Importer for Gravity Forms Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
PDF Importer for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
PDF Importer for Gravity Forms Alternatives
PDF Builder for WPForms
pdf-builder-for-wpforms
The first and only PDF drag and drop builder for WPForms.
PDF Importer for WPForms
pdf-importer-for-wpform
Import a pdf, map it to a form and attaching to any email
PDF Builder for Gravity Forms
pdf-builder-for-gravity
The first and only PDF drag and drop builder for Gravity Forms.
PDF Importer for Ninja Forms
pdf-importer-for-ninjaforms-pro
Import a pdf, map it to a form and attaching to any email
PDF for WPForms + Drag and Drop Template Builder
pdf-for-wpforms
The plugin helps you create PDF for WPForms you can builder PDF template
PDF Importer for Gravity Forms Developer Profile
19 plugins · 12K total installs
How We Detect PDF Importer for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-importer-for-gravity/core/css/Style.css/wp-content/plugins/pdf-importer-for-gravity/core/js/admin/pdf-importer-for-gravity-admin.js/wp-content/plugins/pdf-importer-for-gravity/core/js/pdf-importer-for-gravity.js/wp-content/plugins/pdf-importer-for-gravity/core/js/admin/pdf-importer-for-gravity-admin.js/wp-content/plugins/pdf-importer-for-gravity/core/js/pdf-importer-for-gravity.jspdf-importer-for-gravity/core/css/Style.css?ver=pdf-importer-for-gravity/core/js/admin/pdf-importer-for-gravity-admin.js?ver=pdf-importer-for-gravity/core/js/pdf-importer-for-gravity.js?ver=HTML / DOM Fingerprints
rednaopdfimpgravity_admin_paramsrednaopdfimpgravity_params