Range Slider Addon for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/range-slider-addon-for-gravity-forms

Integrate your gravity forms with a smooth, lightweight, customizable range slider and unrivaled performance on both mobile and desktop.

1K active installs v1.1.7 PHP 5.6+ WP 5.0+ Updated Oct 9, 2025
gravity-form-range-slidergravity-formsrange-sliderslider-inputwordpress-slider
97
A · Safe
CVEs total1
Unpatched0
Last CVEOct 27, 2025
Download
Safety Verdict

Is Range Slider Addon for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 97/100

Range Slider Addon for Gravity Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 27, 2025Updated 5mo ago
Risk Assessment

The 'range-slider-addon-for-gravity-forms' plugin v1.1.7 demonstrates a generally good security posture with several strong practices in place. The complete absence of dangerous functions, 100% prepared SQL statements, and 100% properly escaped output are commendable. The plugin also has a decent number of nonce checks and capability checks relative to its entry points. However, a significant concern is the presence of one AJAX handler without any authentication checks, creating a direct avenue for unauthenticated interaction and potential abuse.

The vulnerability history shows one known CVE, which is concerning, but it is currently patched. The common vulnerability type being Cross-site Scripting (XSS) is a known risk in web applications, and while this specific CVE is patched, it highlights a past area of weakness that developers should remain vigilant about. The lack of taint analysis results might be due to limitations in the analysis tool or that the plugin, despite its attack surface, does not exhibit complex or easily identifiable tainted data flows.

In conclusion, while the plugin implements many security best practices, the single unprotected AJAX endpoint presents a clear and actionable security risk. The past XSS vulnerability, even if patched, warrants ongoing attention to input sanitization. The overall security is moderate, with a key area for immediate improvement being the authentication of all AJAX handlers.

Key Concerns

  • Unprotected AJAX handler
  • Known CVE history (XSS)
Vulnerabilities
1

Range Slider Addon for Gravity Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-49905high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Range Slider Addon for Gravity Forms <= 1.1.6 - Unauthenticated Stored Cross-Site Scripting

Oct 27, 2025 Patched in 1.1.7 (8d)
Code Analysis
Analyzed Mar 16, 2026

Range Slider Addon for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
92 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped92 total outputs
Attack Surface
1 unprotected

Range Slider Addon for Gravity Forms Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 3

authwp_ajax_gfrs_offer_notice_dismissincludes\admin\class-menu.php:14
authwp_ajax_rs_review_dismissincludes\admin\class-menu.php:15
authwp_ajax_upgrade_notice_dismissincludes\admin\class-menu.php:16
WordPress Hooks 15
actiongform_loadedgf-range-slider.php:68
filteradmin_footer_textincludes\admin\class-menu.php:8
actionadmin_menuincludes\admin\class-menu.php:9
actionadmin_enqueue_scriptsincludes\admin\class-menu.php:10
actionadmin_noticesincludes\admin\class-menu.php:11
actionadmin_noticesincludes\admin\class-menu.php:12
actionadmin_noticesincludes\admin\class-menu.php:13
filtergform_tooltipsincludes\fields\class-nu-range-slider.php:37
actiongform_editor_jsincludes\fields\class-nu-range-slider.php:38
filtergform_custom_merge_tagsincludes\fields\class-nu-range-slider.php:39
actiongform_editor_js_set_default_valuesincludes\fields\class-nu-range-slider.php:40
actiongform_enqueue_scriptsincludes\fields\class-nu-range-slider.php:41
filtergform_field_settings_tabsincludes\fields\class-nu-range-slider.php:43
actiongform_field_settings_tab_content_nurange_tabincludes\fields\class-nu-range-slider.php:44
actiongform_field_advanced_settingsincludes\fields\class-nu-range-slider.php:46
Maintenance & Trust

Range Slider Addon for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 9, 2025
PHP min version5.6
Downloads13K

Community Trust

Rating96/100
Number of ratings4
Active installs1K
Developer Profile

Range Slider Addon for Gravity Forms Developer Profile

PluginsCafe

16 plugins · 11K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Range Slider Addon for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/range-slider-addon-for-gravity-forms/assets/css/gfrs_admin.css/wp-content/plugins/range-slider-addon-for-gravity-forms/assets/js/gfrs_admin.js
Script Paths
/wp-content/plugins/range-slider-addon-for-gravity-forms/assets/js/gfrs_admin.js
Version Parameters
range-slider-addon-for-gravity-forms/assets/css/gfrs_admin.css?ver=range-slider-addon-for-gravity-forms/assets/js/gfrs_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
pcafe_wrapperpcafe_container
Data Attributes
data-nonce
JS Globals
GF_NU_RANGE_SLIDER_ADDON_VERSIONGF_NU_RANGE_SLIDER_URLGFRS_GF_MIN_2_5
FAQ

Frequently Asked Questions about Range Slider Addon for Gravity Forms