RT Webhook for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/rt-webhook-for-gravity-forms

An advanced webhook integration for Gravity Forms with field mapping, conditional logic, and custom headers.

0 active installs v2.0.0 PHP + WP 5.0+ Updated Feb 13, 2026
gravity-formsintegrationjsonwebhookzapier
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RT Webhook for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

RT Webhook for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The rt-webhook-for-gravity-forms plugin version 2.0.0 exhibits a strong security posture based on the provided static analysis. The code appears to follow many good security practices, including a very high percentage of properly escaped output and the exclusive use of prepared statements for SQL queries. The absence of dangerous functions, file operations, and critical/high severity taint flows further contributes to its secure design. The plugin also demonstrates an awareness of security by implementing nonce and capability checks, and it has no publicly known vulnerabilities, indicating a history of stable and secure releases.

However, there is one external HTTP request that is not explicitly detailed in its security handling, which represents a potential, albeit minor, area of concern. While the overall attack surface is small and appears to be protected, the presence of this single external request warrants attention. Without further details on how this request is handled, especially regarding any user-supplied data that might be included, it's difficult to definitively assess its risk. Nevertheless, given the plugin's otherwise robust security profile and clean vulnerability history, the overall risk is assessed as low.

The plugin's strengths lie in its clean code practices, minimal attack surface, and lack of historical vulnerabilities. Its main weakness, or rather an area requiring further scrutiny, is the single unexamined external HTTP request. This plugin appears to be a well-maintained and secure option, but vigilance should always be maintained for external interactions.

Key Concerns

  • External HTTP request without explicit security handling
Vulnerabilities
None known

RT Webhook for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RT Webhook for Gravity Forms Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

RT Webhook for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
51 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped52 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<class-rt-webhook-admin> (admin\class-rt-webhook-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RT Webhook for Gravity Forms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_rtwcgf_get_gf_fieldsadmin\class-rt-webhook-admin.php:26
WordPress Hooks 7
actioninitadmin\class-rt-webhook-admin.php:22
actionadmin_menuadmin\class-rt-webhook-admin.php:23
actionadd_meta_boxesadmin\class-rt-webhook-admin.php:24
actionsave_post_rtwcgf_gf_webhookadmin\class-rt-webhook-admin.php:25
actionadmin_enqueue_scriptsadmin\class-rt-webhook-admin.php:27
actiongform_after_submissionincludes\class-rt-webhook-handler.php:22
actionplugins_loadedrt-webhook-for-gravity-forms.php:64
Maintenance & Trust

RT Webhook for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version
Downloads163

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

RT Webhook for Gravity Forms Developer Profile

raintech357

9 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RT Webhook for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rt-webhook-for-gravity-forms/assets/js/admin.js
Script Paths
/wp-content/plugins/rt-webhook-for-gravity-forms/assets/js/admin.js
Version Parameters
rt-webhook-for-gravity-forms/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
badge
Data Attributes
data-gf-field-iddata-mapping-targetdata-mapping-source
JS Globals
rtwcgf_admin
FAQ

Frequently Asked Questions about RT Webhook for Gravity Forms