Telephone field for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/telephone-field-for-gravity-forms

The plugin helps you in creating a country drop-down list with country flag.

300 active installs v1.6.4 PHP 7.2+ WP 2.0+ Updated Mar 11, 2026
gravity-formsgravity-forms-phonephone-fieldphone-formtelephone-field
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Telephone field for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Telephone field for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "telephone-field-for-gravity-forms" plugin version 1.6.4 demonstrates a generally strong security posture based on the provided static analysis. The code correctly utilizes prepared statements for all SQL queries and ensures all output is properly escaped, which are crucial defenses against common web vulnerabilities like SQL injection and cross-site scripting. The plugin also implements a nonce check for its sole AJAX handler, further mitigating risks associated with unauthorized requests. There are no identified critical or high-severity taint flows, and the plugin has no recorded vulnerability history, indicating a history of secure development and maintenance.

However, a notable area for concern is the lack of capability checks on the single AJAX handler. While a nonce check is present, this handler could potentially be triggered by any logged-in user without verifying if they possess the necessary permissions to perform the action. This could lead to privilege escalation or unintended actions if the AJAX endpoint performs sensitive operations. The presence of two external HTTP requests, while not inherently a vulnerability, warrants attention to ensure they are not being used in a way that could expose the site to risks such as SSRF if user-controlled data influences the request targets. The absence of capability checks is the primary weakness identified.

In conclusion, this plugin appears to be well-developed with robust defenses against common attacks like SQL injection and XSS. The lack of reported vulnerabilities is a positive indicator. The main weakness lies in the potential for privilege escalation due to the absence of capability checks on its AJAX endpoint. Addressing this would significantly enhance its overall security. The external HTTP requests should also be reviewed for potential risks.

Key Concerns

  • AJAX handler without capability check
Vulnerabilities
None known

Telephone field for Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Telephone field for Gravity Forms Release Timeline

v1.6.4Current
v1.6.3
v1.6.1
Code Analysis
Analyzed Mar 16, 2026

Telephone field for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
39 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

100% escaped39 total outputs
Attack Surface

Telephone field for Gravity Forms Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 14
actiongform_field_standard_settingsfrontend\settings.php:6
filtergform_settings_menufrontend\settings.php:7
actiongform_settings_gf_ipinfofrontend\settings.php:8
actiongform_editor_jsfrontend\settings.php:9
actionyeeaddons_gf_telephone_settingsfrontend\settings.php:10
actiongform_loadedtelephone-field-for-gravity-forms.php:14
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
Maintenance & Trust

Telephone field for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Telephone field for Gravity Forms Developer Profile

add-ons.org

59 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Telephone field for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/telephone-field-for-gravity-forms/css/telephone.css/wp-content/plugins/telephone-field-for-gravity-forms/js/telephone.js
Script Paths
/wp-content/plugins/telephone-field-for-gravity-forms/js/telephone.js
Version Parameters
telephone-field-for-gravity-forms/css/telephone.css?ver=telephone-field-for-gravity-forms/js/telephone.js?ver=

HTML / DOM Fingerprints

CSS Classes
yeekit_addons_listyee-installyee-pro
Data Attributes
data-plugin-id
JS Globals
Yeeaddons_GF_Telephone_AddOn
FAQ

Frequently Asked Questions about Telephone field for Gravity Forms