Post Picker for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/post-picker-for-gravity-forms

Creates dynamic dropdowns populated with posts from any post type in your Gravity Forms

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Unknown
cptdropdownfieldgravity-formsgravityforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Post Picker for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Post Picker for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The post-picker-for-gravity-forms plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and unsanitized taint flows is highly commendable. Furthermore, all identified outputs are properly escaped, and the plugin avoids file operations and external HTTP requests, significantly reducing common attack vectors. The presence of capability checks, even if only one is noted, is a positive sign for access control.

However, the static analysis also reveals a critical absence of nonce checks and a lack of explicit permission callbacks for any potential REST API routes or AJAX handlers (though none are reported). While the attack surface is currently zero, this lack of protective measures for potential future entry points could become a concern if the plugin evolves. The plugin also has no recorded vulnerability history, which is a positive indicator of its stability and development practices, but it's important to remember that zero history doesn't guarantee future immunity.

In conclusion, the plugin demonstrates good security practices in its current implementation, with a low apparent risk. The main area for caution lies in the lack of defensive measures for potential future entry points. A score of 100 points is appropriate given the absence of exploitable vulnerabilities and good coding practices, with no deductions necessary based on the provided data.

Vulnerabilities
None known

Post Picker for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Post Picker for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface

Post Picker for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actiongform_field_standard_settingsincludes\class-ppfgf-addon.php:122
actiongform_editor_jsincludes\class-ppfgf-addon.php:123
actiongform_loadedincludes\class-ppfgf-bootstrap.php:29
actionadmin_noticesincludes\class-ppfgf-bootstrap.php:31
Maintenance & Trust

Post Picker for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads143

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Post Picker for Gravity Forms Developer Profile

YMMV Plugins

2 plugins · 600 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Picker for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-picker-for-gravity-forms/assets/js/form-editor.js
Version Parameters
post-picker-for-gravity-forms/assets/js/form-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
post_type_settingppfgf-form-editor
Data Attributes
id="ppfgf_post_type"onchange="ppfgfSetPostType(this.value);"
JS Globals
ppfgfSetPostType
FAQ

Frequently Asked Questions about Post Picker for Gravity Forms