Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Security & Risk Analysis

wordpress.org/plugins/sprout-invoices-gravity-forms

Dynamic invoicing (and estimates/quotes) from Gravity Form submissions.

90 active installs v1.3.5 PHP + WP 4.8+ Updated Dec 1, 2025
billingestimatesgravity-formsinvoiceinvoicing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Safe to Use in 2026?

Generally Safe

Score 100/100

Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "sprout-invoices-gravity-forms" v1.3.5 exhibits a strong security posture based on the provided static analysis. The absence of any reported CVEs in its history further reinforces this positive outlook, suggesting a history of diligent security practices and maintenance by the developers. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. Furthermore, there are no identified file operations or external HTTP requests, minimizing common attack vectors.

However, the static analysis does highlight a significant area of concern: the complete absence of nonce checks and capability checks. While the reported attack surface is zero, which is excellent, this lack of authorization checks on any potential (even if currently non-existent) entry points is a considerable weakness. If new entry points were to be introduced in future updates without adequate security measures, they could be exploited. The taint analysis also reported zero flows, which is positive, but the absence of checks means that even if a tainted input were to enter the system, it might not be properly validated or sanitized.

In conclusion, while the current version of the plugin appears to be free of known vulnerabilities and follows many good coding practices, the complete lack of nonce and capability checks represents a notable security gap. This suggests that while the plugin might be secure now due to its limited exposure, it lacks inherent safeguards that would protect it against potential future vulnerabilities if the attack surface expands or if existing code were to be misused. The vulnerability history is a strong positive, but the lack of fundamental security checks is a concerning weakness.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

100% escaped4 total outputs
Attack Surface

Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtergform_pre_renderinc\SI_GF_Integration_Addon.php:31
filtergform_pre_submission_filterinc\SI_GF_Integration_Addon.php:32
filtergform_pre_validationinc\SI_GF_Integration_Addon.php:33
actiongform_loadedsprout-invoices-gravity-forms.php:21
Maintenance & Trust

Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads6K

Community Trust

Rating74/100
Number of ratings3
Active installs90
Developer Profile

Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions Developer Profile

BoldGrid

15 plugins · 1.1M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
841 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sprout-invoices-gravity-forms-integration/assets/css/admin.css/wp-content/plugins/sprout-invoices-gravity-forms-integration/assets/js/admin.js
Script Paths
/wp-content/plugins/sprout-invoices-gravity-forms-integration/assets/js/admin.js
Version Parameters
sprout-invoices-gravity-forms-integration/assets/css/admin.css?ver=sprout-invoices-gravity-forms-integration/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
si_gf_integration_settings_page
Data Attributes
data-si-product-typedata-si-generation
JS Globals
si_gf_int_admin
FAQ

Frequently Asked Questions about Gravity Forms + Sprout Invoices – Easy Invoice & Estimate Submissions