
Shortcodes for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/shortcodes-for-gravity-formsShortcodes for Gravity Forms adds a column in form list to display form shortcodes in backend.
Is Shortcodes for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 85/100Shortcodes for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shortcodes-for-gravity-forms v1.0.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any recorded vulnerabilities in its history, including critical and high severity ones, is a strong indicator of good development practices. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, no external HTTP requests, and no tainted data flows. This suggests a low likelihood of common web vulnerabilities like SQL injection, RCE, or LFI.
However, there are areas for improvement that introduce potential, albeit currently unexploited, risks. The most significant concern is the lack of output escaping for the single output identified. This means that if any user-supplied data were to reach this output without proper sanitization, it could lead to Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce and capability checks across all entry points, while not concerning when the attack surface is zero, would become a critical weakness if any new entry points were introduced without these security measures. The plugin's current minimal attack surface is a mitigating factor for these weaknesses, but it's a fragile defense.
In conclusion, the plugin is currently in a secure state, largely due to its clean vulnerability history and the absence of high-risk code patterns like raw SQL or dangerous functions. The primary concern is the unescaped output, which presents a potential XSS vector. While the zero attack surface is reassuring, the lack of authentication checks on potential entry points is a notable weakness that could be exploited if the plugin evolves to have a larger exposed surface. Vigilance in maintaining this clean history and addressing the output escaping is recommended.
Key Concerns
- Output escaping is not properly implemented
- Nonce checks are missing
- Capability checks are missing
Shortcodes for Gravity Forms Security Vulnerabilities
Shortcodes for Gravity Forms Code Analysis
Output Escaping
Shortcodes for Gravity Forms Attack Surface
WordPress Hooks 3
Maintenance & Trust
Shortcodes for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Shortcodes for Gravity Forms Alternatives
GF Stripe Extensions
gf-stripe-extensions
Add Stripe functions to Wordpress including ApplePay, analytics, query transactions, limit payments and payment recovery to Gravity Forms.
SV Gravity Forms Enhancer
sv-gravity-forms-enhancer
Improves Gravity Forms in various ways.
GravityOps Search – Search and Display Gravity Forms Entries
gravityops-search
Search Gravity Forms entries on the front end and display matching results anywhere. Filter by any field value. Output custom formatted data.
Survey Reporting & Data Analysis Report Add-On for Gravity Forms
survey-reporting-data-analysis-report-add-on-for-gravity-forms
This plugin extends the Gravity Forms plugin and adds a reporting tool onto any existing forms.
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Shortcodes for Gravity Forms Developer Profile
8 plugins · 112K total installs
How We Detect Shortcodes for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[gravityform id="