Gravity Forms Keap Feed Security & Risk Analysis

wordpress.org/plugins/systasis-gf-infusionsoft-feed

Sync form submissions between Gravity Forms and Keap. This version won't work after 31-Dec-2026. See https://systasis.co/category/gfif for more.

200 active installs v3.0.0 PHP 7.0+ WP 5.0+ Updated Mar 30, 2026
add-oncrmgravity-formskeap-infusionsoftsystasis
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gravity Forms Keap Feed Safe to Use in 2026?

Generally Safe

Score 100/100

Gravity Forms Keap Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'systasis-gf-infusionsoft-feed' plugin v3.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified critical or high-severity vulnerabilities in taint analysis, no dangerous functions used, and all SQL queries utilize prepared statements. The plugin demonstrates good practices by implementing capability checks and only performing one file operation. The lack of external HTTP requests and zero shortcodes also contribute to a reduced attack surface. However, a significant concern is the complete absence of nonce checks and the fact that only 67% of output is properly escaped, leaving a portion potentially vulnerable to cross-site scripting (XSS) attacks if the unescaped data is user-controlled or originates from untrusted sources.

The plugin's vulnerability history is clean, with no recorded CVEs. This indicates a history of responsible development or a lack of historical targeting, but it does not negate the potential risks identified in the static analysis. The limited attack surface of zero entry points without authentication is a positive sign, but the unaddressed output escaping and lack of nonce checks on any potential (though currently non-existent) AJAX handlers remain areas of concern for a robust security implementation. Overall, while the plugin has a solid foundation, these specific weaknesses require attention.

Key Concerns

  • Partial output escaping missing
  • No nonce checks on potential entry points
Vulnerabilities
None known

Gravity Forms Keap Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gravity Forms Keap Feed Release Timeline

v3.0
v2.5
Code Analysis
Analyzed Mar 16, 2026

Gravity Forms Keap Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
12 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped18 total outputs
Attack Surface

Gravity Forms Keap Feed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filtergform_entry_metaapp\GravityFormsInfusionsoftIntegrator.php:224
actionadmin_noticesapp\GravityFormsInfusionsoftIntegrator.php:249
filtergform_export_formapp\GravityFormsInfusionsoftIntegrator.php:282
actiongform_forms_post_importapp\GravityFormsInfusionsoftIntegrator.php:283
filtergform_addon_field_map_choicesapp\GravityFormsInfusionsoftIntegrator.php:618
filtergform_addon_field_valueapp\GravityFormsInfusionsoftIntegrator.php:1947
filtergform_export_forminfusionsoftcrm.php:53
actiongform_loadedinfusionsoftcrm.php:60
actionshutdowninfusionsoftcrm.php:63
actionadmin_noticesinfusionsoftcrm.php:91
Maintenance & Trust

Gravity Forms Keap Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 30, 2026
PHP min version7.0
Downloads13K

Community Trust

Rating100/100
Number of ratings5
Active installs200
Developer Profile

Gravity Forms Keap Feed Developer Profile

Systasis Computer Systems

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gravity Forms Keap Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/systasis-gf-infusionsoft-feed/vendor/systasis/gf-feed-addon-framework/feed-addon-framework.js/wp-content/plugins/systasis-gf-infusionsoft-feed/vendor/systasis/gf-feed-addon-framework/feed-addon-framework.css/wp-content/plugins/systasis-gf-infusionsoft-feed/js/dist/gf-infusionsoft-integration.js
Script Paths
/wp-content/plugins/systasis-gf-infusionsoft-feed/vendor/systasis/gf-feed-addon-framework/feed-addon-framework.js/wp-content/plugins/systasis-gf-infusionsoft-feed/js/dist/gf-infusionsoft-integration.js
Version Parameters
systasis-gf-infusionsoft-feed/vendor/systasis/gf-feed-addon-framework/feed-addon-framework.js?ver=systasis-gf-infusionsoft-feed/js/dist/gf-infusionsoft-integration.js?ver=

HTML / DOM Fingerprints

CSS Classes
gfield_gf_infusionsoft_feed_sectiongfield_gf_infusionsoft_feed_headinggfield_gf_infusionsoft_feed_textareagfield_gf_infusionsoft_feed_hidden
Data Attributes
data-gf-infusionsoft-feed-sectiondata-gf-infusionsoft-feed-headingdata-gf-infusionsoft-feed-textareadata-gf-infusionsoft-feed-hidden
JS Globals
gf_infusionsoft_integration_params
FAQ

Frequently Asked Questions about Gravity Forms Keap Feed