
Opayo Form Payment Gateway for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/sagepay-form-payment-gateway-for-gravity-formsAccept card payments in Gravity Forms using Opayo Form (hosted checkout by Elavon)—customers pay on Opayo’s pages, not on your server.
Is Opayo Form Payment Gateway for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Opayo Form Payment Gateway for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "sagepay-form-payment-gateway-for-gravity-forms" version 1.1.9 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs. This suggests a generally mature development process with a focus on preventing common database attacks and a good track record. However, the static analysis reveals a significant concern: one AJAX handler lacks authentication checks. This unprotected entry point creates a direct avenue for potential exploitation if it handles user-supplied data without proper authorization. The absence of taint analysis flows is a limitation, but the identified unprotected AJAX handler is a concrete risk that warrants attention.
Key Concerns
- AJAX handler without authentication
- Low output escaping coverage
Opayo Form Payment Gateway for Gravity Forms Security Vulnerabilities
Opayo Form Payment Gateway for Gravity Forms Release Timeline
Opayo Form Payment Gateway for Gravity Forms Code Analysis
SQL Query Safety
Output Escaping
Opayo Form Payment Gateway for Gravity Forms Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Opayo Form Payment Gateway for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Opayo Form Payment Gateway for Gravity Forms Alternatives
PatSaTECH's Opayo Server Gateway for WooCommerce
patsatech-wc-opayo-server
PatSaTECH's Opayo Server Gateway for accepting payments on your WooCommerce Store.
Gravity Forms Eway
gravityforms-eway
Easily create online payment forms with Gravity Forms and Eway.
PatSaTECH's Opayo Direct Gateway for WooCommerce
sagepay-direct-gateway-for-woocommerce
Accept Opayo Direct card payments in WooCommerce with on-site checkout, Checkout Block support, and HPOS compatibility.
Click & Pledge for Gravity Forms
gravity-forms-click-pledge
Add a credit card payment gateway for Click & Pledge to the Gravity Forms plugin
Paystation (3 Party Hosted) for Gravity forms
gravity-forms-paystation-3-party-hosted
Integrates Gravity Forms with the Paystation 3 party hosted payment gateway allowing end-users to purchase goods and services via Gravity Forms.
Opayo Form Payment Gateway for Gravity Forms Developer Profile
10 plugins · 390 total installs
How We Detect Opayo Form Payment Gateway for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sagepay-form-payment-gateway-for-gravity-forms/sagepay.phpHTML / DOM Fingerprints
gf_sagepay_form_mode_livegf_sagepay_form_mode_testgf_sagepay_form_send_emails_nogf_sagepay_form_send_emails_customergf_sagepay_form_send_emails_vendorgf_sagepay_form_apply3d_truegf_sagepay_form_apply3d_falsegf_sagepay_form_trans_type_payment+2 moredata-gf_sagepay_form_modedata-gf_sagepay_form_vendor_namedata-gf_sagepay_form_vendor_passworddata-gf_sagepay_form_vendor_emaildata-gf_sagepay_form_send_emailsdata-gf_sagepay_form_email_message+2 morewindow.gf_sagepay_form_modewindow.gf_sagepay_form_vendor_namewindow.gf_sagepay_form_vendor_passwordwindow.gf_sagepay_form_vendor_emailwindow.gf_sagepay_form_send_emailswindow.gf_sagepay_form_email_message+2 more