Razorpay for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/razorpay-gravity-forms

Allows you to use Razorpay payment gateway with the gravity forms plugin.

600 active installs v1.3.7 PHP + WP 3.9.2+ Updated Jan 23, 2025
ecommercegravityformsindiapaymentsrazorpay
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Razorpay for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Razorpay for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "razorpay-gravity-forms" v1.3.7 exhibits a mixed security posture. On the positive side, the static analysis indicates a minimal attack surface with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, no unprotected entry points. Furthermore, the absence of dangerous functions and external HTTP requests is a strong security positive. However, several significant concerns arise from the code analysis. The presence of SQL queries without prepared statements is a major red flag, potentially exposing the application to SQL injection vulnerabilities. Additionally, a concerning percentage of output escaping (only 28% proper) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. The taint analysis revealing a flow with unsanitized paths and a high severity risk further amplifies these concerns, indicating a potential for malicious data to be processed without adequate safeguards. The plugin's vulnerability history being clean is a strength, but this is overshadowed by the inherent risks identified within the current code.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
  • Taint flow with unsanitized path (high severity)
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Razorpay for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Razorpay for Gravity Forms Release Timeline

v1.3.7Current
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
v1.2.2
v1.2.1
v1.2.0
v1.1.1
Code Analysis
Analyzed Mar 16, 2026

Razorpay for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
13
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

28% escaped18 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-gf-razorpay> (class-gf-razorpay.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Razorpay for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filtergform_confirmationclass-gf-razorpay.php:166
filtergform_notification_eventsclass-gf-razorpay.php:648
actionadmin_post_nopriv_gf_razorpay_webhookrazorpay.php:24
actiongform_loadedrazorpay.php:25
actionplugins_loadedrazorpay.php:26
actionrzp_gf_webhook_exec_cronrazorpay.php:27
filtercron_schedulesrazorpay.php:29
filtergform_currenciesrazorpay.php:44
Maintenance & Trust

Razorpay for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 23, 2025
PHP min version
Downloads14K

Community Trust

Rating20/100
Number of ratings2
Active installs600
Developer Profile

Razorpay for Gravity Forms Developer Profile

Razorpay

10 plugins · 107K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
22 days
View full developer profile
Detection Fingerprints

How We Detect Razorpay for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/razorpay-gravity-forms/razorpay-gravity-forms.php/wp-content/plugins/razorpay-gravity-forms/class-gf-razorpay.php/wp-content/plugins/razorpay-gravity-forms/supported-currencies.json
Version Parameters
razorpay-gravity-forms/razorpay-gravity-forms.php?ver=razorpay-gravity-forms/class-gf-razorpay.php?ver=

HTML / DOM Fingerprints

Data Attributes
data-gf-razorpay-webhook-secret
JS Globals
window.gf_razorpay_script
REST Endpoints
/wp-json/gf/v2/settings/razorpay-gravity-forms
FAQ

Frequently Asked Questions about Razorpay for Gravity Forms