
Post Picker for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/post-picker-for-gravity-formsCreates dynamic dropdowns populated with posts from any post type in your Gravity Forms
Is Post Picker for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Post Picker for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The post-picker-for-gravity-forms plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and unsanitized taint flows is highly commendable. Furthermore, all identified outputs are properly escaped, and the plugin avoids file operations and external HTTP requests, significantly reducing common attack vectors. The presence of capability checks, even if only one is noted, is a positive sign for access control.
However, the static analysis also reveals a critical absence of nonce checks and a lack of explicit permission callbacks for any potential REST API routes or AJAX handlers (though none are reported). While the attack surface is currently zero, this lack of protective measures for potential future entry points could become a concern if the plugin evolves. The plugin also has no recorded vulnerability history, which is a positive indicator of its stability and development practices, but it's important to remember that zero history doesn't guarantee future immunity.
In conclusion, the plugin demonstrates good security practices in its current implementation, with a low apparent risk. The main area for caution lies in the lack of defensive measures for potential future entry points. A score of 100 points is appropriate given the absence of exploitable vulnerabilities and good coding practices, with no deductions necessary based on the provided data.
Post Picker for Gravity Forms Security Vulnerabilities
Post Picker for Gravity Forms Code Analysis
Output Escaping
Post Picker for Gravity Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Post Picker for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Post Picker for Gravity Forms Alternatives
Country and State Selection Addon for Gravity Forms
gforms-addon-for-country-and-state-selection
Country and State Selection Addon for Gravity Forms lets you easily add dynamic country and state dropdown fields to your Gravity Forms.
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
GravityExport Lite for Gravity Forms
gf-entries-in-excel
Export all Gravity Forms entries to Excel (.xlsx) or CSV via a download button or a secret shareable URL.
Multiple Columns for Gravity Forms
gf-form-multicolumn
Introduces new form elements into Gravity Forms which allow for simple column creation.
Post Picker for Gravity Forms Developer Profile
2 plugins · 600 total installs
How We Detect Post Picker for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-picker-for-gravity-forms/assets/js/form-editor.jspost-picker-for-gravity-forms/assets/js/form-editor.js?ver=HTML / DOM Fingerprints
post_type_settingppfgf-form-editorid="ppfgf_post_type"onchange="ppfgfSetPostType(this.value);"ppfgfSetPostType