
PDF Zip Downloader for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/pdf-zip-downloader-for-gravity-formsGenerates a ZIP file that includes a PDF and the attachments from a Gravity Forms entry.
Is PDF Zip Downloader for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 92/100PDF Zip Downloader for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pdf-zip-downloader-for-gravity-forms" plugin version 1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of any known CVEs, coupled with the use of prepared statements for all SQL queries and a high percentage of properly escaped output, suggests that the developers have prioritized core security practices. The limited attack surface with no exposed AJAX handlers, REST API routes, or shortcodes also contributes positively to its security. Furthermore, the presence of a nonce check is a welcome sign of basic security awareness.
However, the taint analysis reveals a concern: two flows were identified with "unsanitized paths." While these did not result in critical or high severity issues, the presence of unsanitized paths is a potential risk that could be exploited if combined with other factors or in a different context. The lack of capability checks for any entry points, while the attack surface is zero, is a missed opportunity to enforce granular access control should any entry points be introduced in future versions. Overall, the plugin appears relatively secure for its current state, but the taint analysis findings warrant attention to ensure these unsanitized paths do not pose a future risk.
Key Concerns
- Flows with unsanitized paths found in taint analysis
- No capability checks on entry points
PDF Zip Downloader for Gravity Forms Security Vulnerabilities
PDF Zip Downloader for Gravity Forms Code Analysis
Output Escaping
Data Flow Analysis
PDF Zip Downloader for Gravity Forms Attack Surface
WordPress Hooks 5
Maintenance & Trust
PDF Zip Downloader for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
PDF Zip Downloader for Gravity Forms Alternatives
Gravity Forms PDF
gravity-forms-pdf
A basic plugin that allows Gravity Forms Entries to be Viewed and Download in a Printer Friendly PDF Layout
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
GravityExport Lite for Gravity Forms
gf-entries-in-excel
Export all Gravity Forms entries to Excel (.xlsx) or CSV via a download button or a secret shareable URL.
Entry Expiration for Gravity Forms
gravity-forms-entry-expiration
Automatically remove old form entries on a custom, defined schedule
PDF Catalog for WooCommerce
pdf-catalog-woocommerce
Generate dynamic PDF catalogs for WooCommerce products. Allow customers to download shop, category, or single product catalogs including images, price …
PDF Zip Downloader for Gravity Forms Developer Profile
1 plugin · 10 total installs
How We Detect PDF Zip Downloader for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-zip-downloader-for-gravity-forms/assets/css/style.css/wp-content/plugins/pdf-zip-downloader-for-gravity-forms/assets/js/script.js/wp-content/plugins/pdf-zip-downloader-for-gravity-forms/assets/js/script.jspdf-zip-downloader-for-gravity-forms/assets/css/style.css?ver=pdf-zip-downloader-for-gravity-forms/assets/js/script.js?ver=HTML / DOM Fingerprints
<!-- PDF Zip Downloader for Gravity Forms settings start --><!-- PDF Zip Downloader for Gravity Forms settings end --><!-- PDF Zip Downloader for Gravity Forms download column start --><!-- PDF Zip Downloader for Gravity Forms download column end -->name='custom_pdf_id'name='zip_name_fields[]'