Star Rating Field For Gravity Form Security & Risk Analysis

wordpress.org/plugins/star-rating-field-for-gravity-form

Star Rating Field For Gravity Form is free plugin. Star Rating Fields are added to Gravity Form by this plugin. Select a Rating style from 12 availabl …

100 active installs v1.0.0 PHP + WP 5.5+ Updated May 12, 2025
gravity-forms-for-ratingrating-field-for-gravityform
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Star Rating Field For Gravity Form Safe to Use in 2026?

Generally Safe

Score 92/100

Star Rating Field For Gravity Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the "star-rating-field-for-gravity-form" plugin v1.0.0 reveals a seemingly robust security posture with no identified entry points lacking authentication, no dangerous functions, and all SQL queries utilizing prepared statements. The code also demonstrates excellent output escaping practices and avoids file operations and external HTTP requests. This suggests a strong adherence to secure coding principles at the foundational level.

However, the complete absence of nonce checks and capability checks is a significant concern. While the current attack surface appears to be zero, this lack of authorization checks means that if any new entry points are introduced in future versions, or if existing code is modified incorrectly, these new functions could be immediately vulnerable to unauthorized access and manipulation without proper safeguards. The taint analysis also showing zero flows, while positive, is based on a zero-flow analysis, meaning it did not detect any potential data flow issues. This could be due to the plugin's current limited functionality or complexity at version 1.0.0, or it could indicate that the analysis tooling did not find any flows to analyze.

Given the plugin's clean vulnerability history with zero recorded CVEs, it indicates a lack of past exploitable security flaws. This, coupled with the strong adherence to secure coding practices like prepared statements and output escaping, paints a picture of a well-written plugin at this version. Nevertheless, the missing authorization mechanisms remain a critical area for improvement to ensure future security as the plugin evolves.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Star Rating Field For Gravity Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Star Rating Field For Gravity Form Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Star Rating Field For Gravity Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
63 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped63 total outputs
Attack Surface

Star Rating Field For Gravity Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actiongform_field_standard_settingsincludes\admin.php:3
actionadmin_enqueue_scriptsincludes\admin.php:126
actiongform_editor_js_set_default_valuesincludes\admin.php:148
actionwp_enqueue_scriptsstar-rating-field-for-gravity-form.php:37
Maintenance & Trust

Star Rating Field For Gravity Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 12, 2025
PHP min version
Downloads1K

Community Trust

Rating80/100
Number of ratings2
Active installs100
Alternatives

Star Rating Field For Gravity Form Alternatives

No alternatives data available yet.

Developer Profile

Star Rating Field For Gravity Form Developer Profile

howdytheme

20 plugins · 5K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Star Rating Field For Gravity Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/star-rating-field-for-gravity-form/public/jquery.rating/jquery.raty.js/wp-content/plugins/star-rating-field-for-gravity-form/public/js/custom.raty.js
Script Paths
/wp-content/plugins/star-rating-field-for-gravity-form/public/jquery.rating/jquery.raty.js/wp-content/plugins/star-rating-field-for-gravity-form/public/js/custom.raty.js
Version Parameters
star-rating-field-for-gravity-form/public/jquery.rating/jquery.raty.js?ver=star-rating-field-for-gravity-form/public/js/custom.raty.js?ver=

HTML / DOM Fingerprints

CSS Classes
star_rate_imgstar_rate_imgs
Data Attributes
onchange="SetFieldProperty('write_a_notice', this.value);"onchange="SetFieldProperty('rating_icon_on', this.value);"onchange="SetFieldProperty('rating_icon_off', this.value);"
JS Globals
rating_ajax
FAQ

Frequently Asked Questions about Star Rating Field For Gravity Form