RentPress: Gravity Forms Add-on Security & Risk Analysis

wordpress.org/plugins/rentpress-gravity-forms-add-on

RentPress: Gravity Forms Add-on connects your contact forms with your multifamily CRMs.

20 active installs v1.2.1 PHP 7.2+ WP 5.8+ Updated Unknown
apartmentsfloor-plansformsgravityleads
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RentPress: Gravity Forms Add-on Safe to Use in 2026?

Generally Safe

Score 100/100

RentPress: Gravity Forms Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "rentpress-gravity-forms-add-on" v1.2.1 exhibits a strong static security posture based on the provided analysis. The absence of any detected entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The lack of taint analysis findings further reinforces this robust internal security.

However, there are critical areas of concern that detract from an otherwise excellent security profile. The complete absence of nonce checks and capability checks is a significant oversight. This means that even though the attack surface is currently zero, any functionality that might be added in the future, or any hidden functionality, would be completely unprotected against unauthorized access or manipulation. The presence of external HTTP requests without any mention of security considerations for these calls is another potential weakness, as these could be exploited for various attacks if not handled with extreme care.

Given the clean vulnerability history, it suggests that the developers have a history of producing secure code or that the plugin has not been a target of significant vulnerability discovery. Nevertheless, the identified gaps in authorization and authentication mechanisms are substantial risks that need immediate attention. The plugin's strengths lie in its clean coding practices regarding SQL and output handling, but its weaknesses in access control are a significant concern that cannot be overlooked.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests without mention of security
Vulnerabilities
None known

RentPress: Gravity Forms Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RentPress: Gravity Forms Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
9
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface

RentPress: Gravity Forms Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticesrentPressGravityFormsWP.php:26
actionadmin_noticesrentPressGravityFormsWP.php:75
actiongform_loadedrentPressGravityFormsWP.php:80
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:314
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:574
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:674
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:773
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:970
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:979
actiongform_after_submissionsrc\rentPressGravityForms\Leads.php:1128
Maintenance & Trust

RentPress: Gravity Forms Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.2
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

RentPress: Gravity Forms Add-on Developer Profile

30 Lines

3 plugins · 140 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RentPress: Gravity Forms Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rentpress-gravity-forms-add-on/feedsettings.css/wp-content/plugins/rentpress-gravity-forms-add-on/feedsettings.js
Script Paths
/wp-content/plugins/rentpress-gravity-forms-add-on/feedsettings.js
Version Parameters
rentpress-gravity-forms-add-on/feedsettings.css?ver=rentpress-gravity-forms-add-on/feedsettings.js?ver=

HTML / DOM Fingerprints

CSS Classes
rentpress-gravity-forms-add-on
HTML Comments
<!-- Cannot activate RentPress: Gravity Forms Add-on --><!-- Learn more about <a target="_blank" href="https://via.30lines.com/xPdGhGjl">RentPress: Gravity Forms Add-on »</a> --><!-- or <a href="/wp-admin/plugin-install.php?s=rentpress&tab=search&type=term">Download RentPress now »</a> --><!-- build request url -->+1 more
Data Attributes
data-plugin-name="rentpress-gravity-forms-add-on"
JS Globals
window.rentpress_gravity_forms_addon_params
FAQ

Frequently Asked Questions about RentPress: Gravity Forms Add-on