
Smart phone field for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/smart-phone-field-for-gravity-formsA simple and nice plugin to get auto country flag from user ip address on gravity form phone field.
Is Smart phone field for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 100/100Smart phone field for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'smart-phone-field-for-gravity-forms' v2.2.1 exhibits a generally strong security posture based on the provided static analysis. It has a small attack surface, with all entry points protected by authentication checks. The code demonstrates excellent practices regarding SQL queries and output escaping, with nearly all queries using prepared statements and outputs being properly escaped. There are no reported critical or high severity vulnerabilities in its history, and the absence of recorded vulnerabilities suggests a history of secure development or diligent patching. The taint analysis also shows no critical or high severity flows, indicating a low risk of data manipulation vulnerabilities.
However, there are a couple of areas that warrant attention. The presence of a file operation and an external HTTP request, while not inherently insecure, could be potential vectors if not handled with extreme care and proper sanitization. Additionally, the absence of capability checks, while paired with nonce checks, could be a concern in more complex scenarios or if the underlying AJAX actions have sensitive operations. The bundled Freemius library also carries a minor risk, as outdated libraries can sometimes harbor unknown vulnerabilities. Overall, the plugin appears secure, but these minor points prevent it from achieving a perfect score.
Key Concerns
- File operation detected
- External HTTP request detected
- No capability checks on AJAX
- Bundled outdated library (Freemius v1.0)
Smart phone field for Gravity Forms Security Vulnerabilities
Smart phone field for Gravity Forms Code Analysis
Bundled Libraries
Output Escaping
Smart phone field for Gravity Forms Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Smart phone field for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Smart phone field for Gravity Forms Alternatives
Flagged Phone Field
flagged-phone-field
The Flagged Phone Field plugin is a powerful tool designed for WordPress, offering advanced customization for phone number fields.
Smart Phone Field For WPForms, Contact Form 7, Fluent Forms, Elementor Forms, WooCommerce
smart-phone-field-for-wp-forms
Instruct your visitors to choose their country code when entering their mobile number to ensure accurate and correctly formatted data submissions.
Phone Validator with Flags for WooCommerce
phone-validator-with-flags-for-woocommerce
Adds a country flag and phone validation to the checkout phone field.
Softech Country Phone Validator
softech-country-phone-validator
Add phone input with country flags, dial codes, and validation to WordPress forms and WooCommerce checkout (classic + blocks).
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Smart phone field for Gravity Forms Developer Profile
16 plugins · 11K total installs
How We Detect Smart phone field for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-phone-field-for-gravity-forms/assets/css/spf_admin.css/wp-content/plugins/smart-phone-field-for-gravity-forms/assets/js/spf_admin_script.js/wp-content/plugins/smart-phone-field-for-gravity-forms/freemius/start.phpsmart-phone-field-for-gravity-forms/assets/css/spf_admin.css?ver=smart-phone-field-for-gravity-forms/assets/js/spf_admin_script.js?ver=HTML / DOM Fingerprints
pcafe_spf_review_noticepcafe_gfspf_review_noticepcafe_spf_dashboardpcafe_containerdata-nonceGF_SMART_PHONE_FIELD_URLGF_SMART_PHONE_FIELD_VERSION_NUM