
Store Locator Plus® | Gravity Forms Locations Security & Risk Analysis
wordpress.org/plugins/slp-gravity-forms-locationsSLP Gravity Forms Locations is an add-on pack for Store Locator Plus that supports adding basic locations using Gravity Forms.
Is Store Locator Plus® | Gravity Forms Locations Safe to Use in 2026?
Generally Safe
Score 85/100Store Locator Plus® | Gravity Forms Locations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'slp-gravity-forms-locations' plugin, in version 6.1.1, exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has a high rate of properly escaped output. The absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase in the past. However, significant concerns arise from its attack surface and code signals. The presence of a single AJAX handler without authentication checks represents a critical vulnerability point, potentially allowing unauthorized actions. Furthermore, the use of the 'create_function' dangerous function, while not directly exploitable without a specific vulnerability path, is a code smell that can lead to security issues in the future and is often a precursor to vulnerabilities. The plugin also includes the Freemius v1.0 library, which, depending on its age and patching status, could introduce its own risks if outdated.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: create_function
- Bundled outdated library: Freemius v1.0
Store Locator Plus® | Gravity Forms Locations Security Vulnerabilities
Store Locator Plus® | Gravity Forms Locations Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Store Locator Plus® | Gravity Forms Locations Attack Surface
AJAX Handlers 1
WordPress Hooks 24
Maintenance & Trust
Store Locator Plus® | Gravity Forms Locations Maintenance & Trust
Maintenance Signals
Community Trust
Store Locator Plus® | Gravity Forms Locations Alternatives
Store Locator Plus® | Extended Data Manager
slp-extended-data-manager
SLP Extended Data Manager is an add-on pack for Store Locator Plus that lets admin manage the extended data settings.
WP Gravity Forms HubSpot
gf-hubspot
Gravity Forms HubSpot Add-on sends Gravity Forms entries to HubSpot.
WP Gravity Forms Keap/Infusionsoft
gf-infusionsoft
Gravity Forms Keap/infusionsoft Add-on sends Gravity Forms entries to infusionsoft/Keap CRM.
WP Gravity Forms Dynamics CRM
gf-dynamics-crm
Gravity Forms Dynamics CRM Add-on sends Gravity Forms entries to Dynamics CRM Online.
WP Gravity Forms Zendesk
gf-zendesk
Gravity Forms Zendesk Add-on sends Gravity Forms entries to Zendesk.
Store Locator Plus® | Gravity Forms Locations Developer Profile
7 plugins · 6K total installs
How We Detect Store Locator Plus® | Gravity Forms Locations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slp-gravity-forms-locations/css/slp-gfl.css/wp-content/plugins/slp-gravity-forms-locations/js/slp-gfl-admin.js/wp-content/plugins/slp-gravity-forms-locations/js/slp-gfl.js/wp-content/plugins/slp-gravity-forms-locations/js/slp-gfl-admin.js/wp-content/plugins/slp-gravity-forms-locations/js/slp-gfl.js/wp-content/plugins/slp-gravity-forms-locations/css/slp-gfl.css?ver=/wp-content/plugins/slp-gravity-forms-locations/js/slp-gfl-admin.js?ver=/wp-content/plugins/slp-gravity-forms-locations/js/slp-gfl.js?ver=HTML / DOM Fingerprints
slp_gfl_admin_pageslp_gfl_admin_page_pricing<!-- DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK. --><!-- If the include/module/submodule/class.php file exists, load it. -->SLP_GFL_FREEMIUS_IDSLP_GFL_SHORT_SLUGSLP_GFL_PREMIUM_SLUGSLP_GFL_ADMIN_PAGE_SLUGSLP_GFL_ADMIN_PAGE_SLUG_FRESLP_GFL_CLASS_PREFIX+5 more