
SecurePay For GravityForms Security & Risk Analysis
wordpress.org/plugins/securepay-for-gravityformsSecurePay payment platform plugin for Gravity Forms.
Is SecurePay For GravityForms Safe to Use in 2026?
Generally Safe
Score 85/100SecurePay For GravityForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "securepay-for-gravityforms" v1.0.12 plugin demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, critical taint flows, raw SQL queries, or significant attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events without proper checks is highly positive. The code also incorporates nonce and capability checks, which are essential for securing WordPress functionalities.
However, a notable concern arises from the output escaping. With only 42% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied or dynamic data displayed on the frontend or within the WordPress admin area could be maliciously injected and executed by other users, potentially leading to session hijacking, defacement, or other security breaches. The single external HTTP request, while not inherently a vulnerability, warrants attention to ensure it is made to a trusted and secure endpoint, and that any data sent or received is handled with appropriate security measures.
Given the clean vulnerability history and the presence of good security practices like prepared statements and checks, the plugin appears well-maintained. Nevertheless, the unescaped output is a critical weakness that significantly lowers its overall security score and requires immediate attention.
Key Concerns
- Significant percentage of unescaped output
- External HTTP request present
SecurePay For GravityForms Security Vulnerabilities
SecurePay For GravityForms Code Analysis
Bundled Libraries
Output Escaping
SecurePay For GravityForms Attack Surface
WordPress Hooks 15
Maintenance & Trust
SecurePay For GravityForms Maintenance & Trust
Maintenance Signals
Community Trust
SecurePay For GravityForms Alternatives
SecurePay For WooCommerce
securepay
SecurePay payment platform plugin for WooCommerce.
SecurePay For Fluent Forms
securepay-for-fluentforms
SecurePay payment platform plugin for Fluent Forms.
SecurePay For GiveWP
securepay-for-givewp
SecurePay payment platform plugin for GiveWP.
SecurePay For Paid Memberships Pro
securepay-for-paidmembershipspro
SecurePay payment platform plugin for Paid Memberships Pro.
SecurePay For WPForms
securepay-for-wpforms
SecurePay payment platform plugin for WPForms.
SecurePay For GravityForms Developer Profile
8 plugins · 260 total installs
How We Detect SecurePay For GravityForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/securepay-for-gravityforms/includes/js/securepay-gf-admin.js/wp-content/plugins/securepay-for-gravityforms/includes/css/securepay-gf-admin.css/wp-content/plugins/securepay-for-gravityforms/includes/js/securepay-gf-admin.jssecurepay-for-gravityforms/includes/js/securepay-gf-admin.js?ver=securepay-for-gravityforms/includes/css/securepay-gf-admin.css?ver=HTML / DOM Fingerprints
gf_securepay_settings_containerSecurePay for Gravityforms.Accept payment by using SecurePay. A Secure Marketplace Platform for Malaysian.data-gf-securepay-public-keydata-gf-securepay-keySecurePayGFM