Smart phone field for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/smart-phone-field-for-gravity-forms

A simple and nice plugin to get auto country flag from user ip address on gravity form phone field.

5K active installs v2.2.1 PHP 7.4+ WP 5.0+ Updated Feb 5, 2026
gravityformsinternational-phone-inputphone-fieldphone-validationsmart-phone-field
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Smart phone field for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Smart phone field for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'smart-phone-field-for-gravity-forms' v2.2.1 exhibits a generally strong security posture based on the provided static analysis. It has a small attack surface, with all entry points protected by authentication checks. The code demonstrates excellent practices regarding SQL queries and output escaping, with nearly all queries using prepared statements and outputs being properly escaped. There are no reported critical or high severity vulnerabilities in its history, and the absence of recorded vulnerabilities suggests a history of secure development or diligent patching. The taint analysis also shows no critical or high severity flows, indicating a low risk of data manipulation vulnerabilities.

However, there are a couple of areas that warrant attention. The presence of a file operation and an external HTTP request, while not inherently insecure, could be potential vectors if not handled with extreme care and proper sanitization. Additionally, the absence of capability checks, while paired with nonce checks, could be a concern in more complex scenarios or if the underlying AJAX actions have sensitive operations. The bundled Freemius library also carries a minor risk, as outdated libraries can sometimes harbor unknown vulnerabilities. Overall, the plugin appears secure, but these minor points prevent it from achieving a perfect score.

Key Concerns

  • File operation detected
  • External HTTP request detected
  • No capability checks on AJAX
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

Smart phone field for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Smart phone field for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
92 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

99% escaped93 total outputs
Attack Surface

Smart phone field for Gravity Forms Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_plc_review_dismissadmin\class-admin.php:14
authwp_ajax_pcafe_offer_notice_dismissadmin\class-admin.php:15
WordPress Hooks 13
filteradmin_footer_textadmin\class-admin.php:8
actionadmin_menuadmin\class-admin.php:9
actionadmin_enqueue_scriptsadmin\class-admin.php:10
actionadmin_noticesadmin\class-admin.php:12
actionadmin_noticesadmin\class-admin.php:13
filtergform_tooltipsclass-spf-free.php:101
actiongform_editor_jsclass-spf-free.php:102
filtergform_field_css_classclass-spf-free.php:104
filtergform_register_init_scriptsclass-spf-free.php:105
filtergform_field_contentclass-spf-free.php:107
filtergform_field_settings_tabsclass-spf-free.php:109
actiongform_field_settings_tab_content_spf_phone_tabclass-spf-free.php:110
actiongform_loadedgravityforms-smart-phone-field.php:69
Maintenance & Trust

Smart phone field for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version7.4
Downloads59K

Community Trust

Rating84/100
Number of ratings22
Active installs5K
Developer Profile

Smart phone field for Gravity Forms Developer Profile

PluginsCafe

16 plugins · 11K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Smart phone field for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-phone-field-for-gravity-forms/assets/css/spf_admin.css/wp-content/plugins/smart-phone-field-for-gravity-forms/assets/js/spf_admin_script.js
Script Paths
/wp-content/plugins/smart-phone-field-for-gravity-forms/freemius/start.php
Version Parameters
smart-phone-field-for-gravity-forms/assets/css/spf_admin.css?ver=smart-phone-field-for-gravity-forms/assets/js/spf_admin_script.js?ver=

HTML / DOM Fingerprints

CSS Classes
pcafe_spf_review_noticepcafe_gfspf_review_noticepcafe_spf_dashboardpcafe_container
Data Attributes
data-nonce
JS Globals
GF_SMART_PHONE_FIELD_URLGF_SMART_PHONE_FIELD_VERSION_NUM
FAQ

Frequently Asked Questions about Smart phone field for Gravity Forms