
Star Rating Field For Gravity Form Security & Risk Analysis
wordpress.org/plugins/star-rating-field-for-gravity-formStar Rating Field For Gravity Form is free plugin. Star Rating Fields are added to Gravity Form by this plugin. Select a Rating style from 12 availabl …
Is Star Rating Field For Gravity Form Safe to Use in 2026?
Generally Safe
Score 92/100Star Rating Field For Gravity Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "star-rating-field-for-gravity-form" plugin v1.0.0 reveals a seemingly robust security posture with no identified entry points lacking authentication, no dangerous functions, and all SQL queries utilizing prepared statements. The code also demonstrates excellent output escaping practices and avoids file operations and external HTTP requests. This suggests a strong adherence to secure coding principles at the foundational level.
However, the complete absence of nonce checks and capability checks is a significant concern. While the current attack surface appears to be zero, this lack of authorization checks means that if any new entry points are introduced in future versions, or if existing code is modified incorrectly, these new functions could be immediately vulnerable to unauthorized access and manipulation without proper safeguards. The taint analysis also showing zero flows, while positive, is based on a zero-flow analysis, meaning it did not detect any potential data flow issues. This could be due to the plugin's current limited functionality or complexity at version 1.0.0, or it could indicate that the analysis tooling did not find any flows to analyze.
Given the plugin's clean vulnerability history with zero recorded CVEs, it indicates a lack of past exploitable security flaws. This, coupled with the strong adherence to secure coding practices like prepared statements and output escaping, paints a picture of a well-written plugin at this version. Nevertheless, the missing authorization mechanisms remain a critical area for improvement to ensure future security as the plugin evolves.
Key Concerns
- Missing nonce checks
- Missing capability checks
Star Rating Field For Gravity Form Security Vulnerabilities
Star Rating Field For Gravity Form Release Timeline
Star Rating Field For Gravity Form Code Analysis
Output Escaping
Star Rating Field For Gravity Form Attack Surface
WordPress Hooks 4
Maintenance & Trust
Star Rating Field For Gravity Form Maintenance & Trust
Maintenance Signals
Community Trust
Star Rating Field For Gravity Form Alternatives
No alternatives data available yet.
Star Rating Field For Gravity Form Developer Profile
20 plugins · 5K total installs
How We Detect Star Rating Field For Gravity Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/star-rating-field-for-gravity-form/public/jquery.rating/jquery.raty.js/wp-content/plugins/star-rating-field-for-gravity-form/public/js/custom.raty.js/wp-content/plugins/star-rating-field-for-gravity-form/public/jquery.rating/jquery.raty.js/wp-content/plugins/star-rating-field-for-gravity-form/public/js/custom.raty.jsstar-rating-field-for-gravity-form/public/jquery.rating/jquery.raty.js?ver=star-rating-field-for-gravity-form/public/js/custom.raty.js?ver=HTML / DOM Fingerprints
star_rate_imgstar_rate_imgsonchange="SetFieldProperty('write_a_notice', this.value);"onchange="SetFieldProperty('rating_icon_on', this.value);"onchange="SetFieldProperty('rating_icon_off', this.value);"rating_ajax