Gravity Booster – Styles & Layouts for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/styles-and-layouts-for-gravity-forms

Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …

40K active installs v5.26 PHP + WP 4.0+ Updated Sep 25, 2025
gravity-forms-cssgravity-forms-designgravity-forms-stylergravity-forms-tooltips
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Booster – Styles & Layouts for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Gravity Booster – Styles & Layouts for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "styles-and-layouts-for-gravity-forms" plugin v5.26 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with all 17 identified AJAX entry points protected by nonce checks and an impressive 99% of outputs being properly escaped. The absence of direct SQL queries without prepared statements and the lack of file operations or bundled libraries further contribute to its secure foundation. The single external HTTP request is a minor point of interest but is unlikely to pose a significant risk without further context.

While the static analysis reveals no critical or high-severity issues, the presence of two "flows with unsanitized paths" in the taint analysis, although not categorized as critical or high, warrants attention. These flows indicate potential pathways where untrusted input could be processed without sufficient sanitization, which, in a more complex scenario, could lead to vulnerabilities. The plugin's historical data is a significant strength, with zero known CVEs, indicating a consistent track record of security.

Overall, the plugin is well-secured, particularly in its handling of user input and access control for its AJAX handlers. The main area for potential improvement lies in thoroughly investigating and sanitizing the identified unsanitized paths, even if they are not currently classified as high-risk. The lack of any historical vulnerabilities is a powerful testament to the developers' commitment to security.

Key Concerns

  • Taint flows with unsanitized paths
Vulnerabilities
None known

Gravity Booster – Styles & Layouts for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gravity Booster – Styles & Layouts for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
1646 escaped
Nonce Checks
17
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped1656 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

8 flows2 with unsanitized paths
<html-template-preview> (helpers\utils\html-template-preview.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Gravity Booster – Styles & Layouts for Gravity Forms Attack Surface

Entry Points17
Unprotected0

AJAX Handlers 17

authwp_ajax_gf_stla_review_actionhelpers\utils\class-gf-stla-review.php:18
authwp_ajax_stla_anit_spam_settingsincludes\admin\fetch\stla-admin-fetch-anispam.php:45
authwp_ajax_stla_save_antispam_settingsincludes\admin\fetch\stla-admin-fetch-anispam.php:46
authwp_ajax_stla_antispam_user_roles_dataincludes\admin\fetch\stla-admin-fetch-anispam.php:47
authwp_ajax_stla_gravity_form_htmlincludes\admin\fetch\stla-admin-fetch-content-area.php:18
authwp_ajax_stla_gravity_form_confirmation_htmlincludes\admin\fetch\stla-admin-fetch-content-area.php:19
authwp_ajax_stla_get_page_countincludes\admin\fetch\stla-admin-fetch-content-area.php:20
authwp_ajax_stla_styler_settingsincludes\admin\fetch\stla-admin-fetch-content-area.php:21
authwp_ajax_stla_styler_fields_settingsincludes\admin\fetch\stla-admin-fetch-content-area.php:22
authwp_ajax_stla_get_forms_with_stylingincludes\admin\fetch\stla-admin-fetch-content-area.php:24
authwp_ajax_stla_delete_forms_stylesincludes\admin\fetch\stla-admin-fetch-content-area.php:25
authwp_ajax_stla_save_styler_settingsincludes\admin\fetch\stla-admin-fetch-content-area.php:26
authwp_ajax_stla_save_booster_settingsincludes\admin\fetch\stla-admin-fetch-content-area.php:27
authwp_ajax_stla_general_settingsincludes\admin\fetch\stla-admin-fetch-content-area.php:28
authwp_ajax_stla_booster_settingsincludes\admin\fetch\stla-admin-fetch-content-area.php:29
authwp_ajax_stla_form_fields_labelsincludes\admin\fetch\stla-admin-fetch-content-area.php:30
authwp_ajax_stla_get_all_form_namesincludes\admin\fetch\stla-admin-fetch-content-area.php:31
WordPress Hooks 34
actionadmin_menuadmin-menu\class-gf-stla-welcome-page.php:12
actionadmin_menuadmin-menu\class-stla-addons-page.php:11
actionadmin_enqueue_scriptsadmin-menu\class-stla-addons-page.php:22
actionplugins_loadedadmin-menu\class-stla-addons-page.php:144
actionadmin_menuadmin-menu\class-stla-license-page.php:11
actionadmin_initadmin-menu\class-stla-license-page.php:12
filterpre_set_site_transient_update_pluginsadmin-menu\EDD_SL_Plugin_Updater.php:75
filterplugins_apiadmin-menu\EDD_SL_Plugin_Updater.php:76
actionafter_plugin_rowadmin-menu\EDD_SL_Plugin_Updater.php:77
actionadmin_initadmin-menu\EDD_SL_Plugin_Updater.php:78
actioninithelpers\utils\class-gf-stla-review.php:17
actionadmin_noticeshelpers\utils\class-gf-stla-review.php:27
actionnetwork_admin_noticeshelpers\utils\class-gf-stla-review.php:28
actionuser_admin_noticeshelpers\utils\class-gf-stla-review.php:29
filtergform_entry_is_spamincludes\antispam\emails\class-stla-antispam-email-mark-spam.php:57
filtergform_validationincludes\antispam\emails\class-stla-antispam-email-restrict-submission.php:55
filtergform_entry_is_spamincludes\antispam\keywords\stla-antispam-keyword-mark-spam.php:50
filtergform_validationincludes\antispam\keywords\stla-antispam-keyword-precheck.php:49
filtergform_form_argsincludes\antispam\userRestrictions\stla-antispam-user-restrictions.php:46
filtergform_form_not_found_messageincludes\antispam\userRestrictions\stla-antispam-user-restrictions.php:47
actioncustomize_registerstyles-layouts-gravity-forms.php:79
actioncustomize_controls_enqueue_scriptsstyles-layouts-gravity-forms.php:80
actioncustomize_preview_initstyles-layouts-gravity-forms.php:81
actionwp_enqueue_scriptsstyles-layouts-gravity-forms.php:82
actionadmin_initstyles-layouts-gravity-forms.php:84
actioncustomize_save_afterstyles-layouts-gravity-forms.php:85
actionadmin_noticesstyles-layouts-gravity-forms.php:86
filtergform_toolbar_menustyles-layouts-gravity-forms.php:87
actiongform_enqueue_scriptsstyles-layouts-gravity-forms.php:88
filtertemplate_includestyles-layouts-gravity-forms.php:90
filterquery_varsstyles-layouts-gravity-forms.php:97
actionadmin_enqueue_scriptsstyles-layouts-gravity-forms.php:100
filtergform_addon_navigationstyles-layouts-gravity-forms.php:101
actionplugins_loadedstyles-layouts-gravity-forms.php:1240
Maintenance & Trust

Gravity Booster – Styles & Layouts for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version
Downloads1.3M

Community Trust

Rating92/100
Number of ratings196
Active installs40K
Developer Profile

Gravity Booster – Styles & Layouts for Gravity Forms Developer Profile

wpmonks

6 plugins · 71K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Booster – Styles & Layouts for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/styles-and-layouts-for-gravity-forms/build/index.css/wp-content/plugins/styles-and-layouts-for-gravity-forms/build/index.js
Script Paths
/wp-content/plugins/styles-and-layouts-for-gravity-forms/build/index.js
Version Parameters
/wp-content/plugins/styles-and-layouts-for-gravity-forms/build/index.js?ver=/wp-content/plugins/styles-and-layouts-for-gravity-forms/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
stla-gravity-booster
HTML Comments
<!-- STLA Addon Menu -->
Data Attributes
data-stla-form-iddata-stla-customizer-url
JS Globals
stlaAdminGravityBooster
FAQ

Frequently Asked Questions about Gravity Booster – Styles & Layouts for Gravity Forms