Surbma | Divi & Gravity Forms Security & Risk Analysis

wordpress.org/plugins/surbma-divi-gravity-forms

Responsive Divi form styles for Gravity Forms.

9K active installs v5.1 PHP 7.0+ WP 5.3+ Updated Apr 8, 2023
divigravity-formsgravityforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surbma | Divi & Gravity Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Surbma | Divi & Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of "surbma-divi-gravity-forms" v5.1 reveals a strong security posture regarding common web vulnerabilities. The plugin demonstrates excellent adherence to best practices by implementing 100% prepared statements for all SQL queries, proper output escaping for all identified outputs, and the absence of file operations or external HTTP requests. Furthermore, the attack surface is minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events identified. The taint analysis also shows no concerning flows, indicating no obvious vulnerabilities related to unsanitized data. The vulnerability history is equally positive, with zero recorded CVEs, suggesting a history of secure development and maintenance.

Despite the overwhelmingly positive findings, the complete absence of nonce checks and capability checks across all potential entry points (even though there are none identified) is a notable concern. While the current attack surface is zero, any future addition of AJAX handlers, REST API routes, or other interactive elements without these fundamental security measures could introduce significant vulnerabilities. The lack of these checks is a gap in the security framework that, while not currently exploitable, represents a potential risk should the plugin evolve. Therefore, while the current version is highly secure based on the provided data, future development should prioritize the implementation of nonce and capability checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Surbma | Divi & Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Surbma | Divi & Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped16 total outputs
Attack Surface

Surbma | Divi & Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedsurbma-divi-gravity-forms.php:23
actiongform_enqueue_scriptssurbma-divi-gravity-forms.php:28
Maintenance & Trust

Surbma | Divi & Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 8, 2023
PHP min version7.0
Downloads172K

Community Trust

Rating100/100
Number of ratings21
Active installs9K
Developer Profile

Surbma | Divi & Gravity Forms Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | Divi & Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/surbma-divi-gravity-forms/css/surbma-divi-gravity-forms.css
Version Parameters
surbma-divi-gravity-forms/css/surbma-divi-gravity-forms.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Surbma | Divi & Gravity Forms