Shift8 Integration for Gravity Forms and SAP Business One Security & Risk Analysis

wordpress.org/plugins/shift8-integration-for-gravity-forms-and-sap-business-one

Integrates Gravity Forms with SAP Business One to automatically create Business Partner records from form submissions.

0 active installs v1.4.9 PHP 7.4+ WP 5.0+ Updated Unknown
business-onecrmgravity-formsintegrationsap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shift8 Integration for Gravity Forms and SAP Business One Safe to Use in 2026?

Generally Safe

Score 100/100

Shift8 Integration for Gravity Forms and SAP Business One has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the 'shift8-integration-for-gravity-forms-and-sap-business-one' plugin version 1.4.9 indicates a generally good security posture. The plugin demonstrates strong adherence to security best practices by utilizing prepared statements for all SQL queries and performing output escaping on a high percentage of outputs. The absence of known CVEs and a clean vulnerability history further bolster this positive assessment. The plugin also incorporates nonce and capability checks, which are crucial for securing entry points.

However, a closer look at the static analysis reveals a potential area of concern: one flow with an unsanitized path identified in the taint analysis. While no critical or high-severity vulnerabilities were flagged, any unsanitized path represents a potential avenue for exploitation, especially if user-supplied data is involved. The presence of file operations and external HTTP requests, while not inherently insecure, necessitates careful review to ensure they are implemented securely and do not introduce vulnerabilities. The limited number of entry points and the absence of unprotected ones are significant strengths, but the single identified taint flow warrants attention.

In conclusion, the plugin exhibits a commendable security foundation with its secure coding practices and lack of historical vulnerabilities. The primary point of vigilance should be the identified unsanitized path, which requires further investigation to confirm if it poses a practical risk. Overall, the plugin appears relatively secure, but the taint analysis finding suggests a need for due diligence.

Key Concerns

  • Flow with unsanitized path identified
  • One file operation present
  • Three external HTTP requests present
Vulnerabilities
None known

Shift8 Integration for Gravity Forms and SAP Business One Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shift8 Integration for Gravity Forms and SAP Business One Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
165 escaped
Nonce Checks
9
Capability Checks
4
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

91% escaped182 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<shift8-gravitysap> (shift8-gravitysap.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shift8 Integration for Gravity Forms and SAP Business One Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_shift8_gravitysap_test_connectionadmin\class-shift8-gravitysap-admin.php:39
authwp_ajax_retry_sap_submissionshift8-gravitysap.php:244
authwp_ajax_load_itemcodesshift8-gravitysap.php:245
WordPress Hooks 18
actionadmin_menuadmin\class-shift8-gravitysap-admin.php:34
actionadmin_initadmin\class-shift8-gravitysap-admin.php:35
actionadmin_enqueue_scriptsadmin\class-shift8-gravitysap-admin.php:36
filtershift8_gravitysap_sslverifyshift8-gravitysap.php:166
actionadmin_noticesshift8-gravitysap.php:174
actionplugins_loadedshift8-gravitysap.php:231
actiongform_after_submissionshift8-gravitysap.php:236
filtergform_entry_list_columnsshift8-gravitysap.php:239
filtergform_entries_field_valueshift8-gravitysap.php:240
filtergform_get_entriesshift8-gravitysap.php:241
actionadmin_footershift8-gravitysap.php:246
filtergform_validationshift8-gravitysap.php:250
actioninitshift8-gravitysap.php:296
actionadmin_noticesshift8-gravitysap.php:298
filtergform_form_settings_menushift8-gravitysap.php:329
actiongform_form_settings_page_sap_integrationshift8-gravitysap.php:332
filtergform_pre_form_settings_saveshift8-gravitysap.php:335
filtergform_validation_messageshift8-gravitysap.php:3730
Maintenance & Trust

Shift8 Integration for Gravity Forms and SAP Business One Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Shift8 Integration for Gravity Forms and SAP Business One Developer Profile

shift8

11 plugins · 980 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shift8 Integration for Gravity Forms and SAP Business One

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shift8-integration-for-gravity-forms-and-sap-business-one/assets/css/shift8-gravitysap.css/wp-content/plugins/shift8-integration-for-gravity-forms-and-sap-business-one/assets/js/shift8-gravitysap.js
Script Paths
/wp-content/plugins/shift8-integration-for-gravity-forms-and-sap-business-one/assets/js/shift8-gravitysap.js
Version Parameters
shift8-integration-for-gravity-forms-and-sap-business-one/assets/css/shift8-gravitysap.css?ver=shift8-integration-for-gravity-forms-and-sap-business-one/assets/js/shift8-gravitysap.js?ver=

HTML / DOM Fingerprints

JS Globals
SHIFT8_GRAVITYSAP_VERSIONSHIFT8_GRAVITYSAP_PLUGIN_FILESHIFT8_GRAVITYSAP_PLUGIN_DIRSHIFT8_GRAVITYSAP_PLUGIN_URLSHIFT8_GRAVITYSAP_PLUGIN_BASENAMESHIFT8_GRAVITYSAP_LOG_FILE
FAQ

Frequently Asked Questions about Shift8 Integration for Gravity Forms and SAP Business One