Search Field for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/search-field-for-gravity-forms

Searches selected post types after a user types, displaying results below field.

100 active installs v1.2.1 PHP 5.6+ WP 5.5+ Updated Dec 8, 2025
gravity-formsgravityformssearch
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Search Field for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Search Field for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "search-field-for-gravity-forms" plugin, version 1.2.1, exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, file operations, and external HTTP requests is positive. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The presence of a nonce check on its entry points further contributes to a more secure foundation. However, the lack of capability checks on its AJAX handlers is a significant concern, as it implies that any authenticated user, regardless of their role or permissions, could potentially interact with these handlers. While the taint analysis and vulnerability history show no known issues, this could be due to a lack of comprehensive testing or the plugin being relatively obscure. The critical weakness lies in the missing authorization checks for its entry points, which could lead to unauthorized actions if exploited.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Search Field for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Search Field for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped22 total outputs
Attack Surface

Search Field for Gravity Forms Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wpsunshine_gf_searchincludes\class-wpsunshine-search-gf-field.php:30
noprivwp_ajax_wpsunshine_gf_searchincludes\class-wpsunshine-search-gf-field.php:31
WordPress Hooks 3
filtergform_tooltipsclass-gfwpsunshinesearchfieldaddon.php:35
actiongform_field_standard_settingsclass-gfwpsunshinesearchfieldaddon.php:36
actiongform_loadedgravityforms-search.php:16
Maintenance & Trust

Search Field for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Search Field for Gravity Forms Developer Profile

WP Sunshine

5 plugins · 4K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Search Field for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/search-field-for-gravity-forms/images/search.svg
Version Parameters
/wp-content/plugins/search-field-for-gravity-forms/

HTML / DOM Fingerprints

CSS Classes
wpsunshine-gf-search-loadingwpsunshine-gf-search-results
Data Attributes
wpsunshine_search_settingwpsunshine_search_per_page_valuewpsunshine_search_result_format_value
JS Globals
wpsunshine_search_
REST Endpoints
/wp-json/wpsunshine/gf/search
FAQ

Frequently Asked Questions about Search Field for Gravity Forms