
Vandar.io Gravityform Security & Risk Analysis
wordpress.org/plugins/vandar-gravityformپرداخت اینترنتی وجه به وسیله درگاه پرداخت واسط وندار
Is Vandar.io Gravityform Safe to Use in 2026?
Generally Safe
Score 85/100Vandar.io Gravityform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vandar-gravityform plugin v2.1.1 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The plugin has no known vulnerabilities or CVEs, which is a strong indicator of good development practices and diligent security auditing. The attack surface is also minimal, with only one AJAX handler, and importantly, it has no unprotected entry points. The absence of critical or high severity taint flows further reinforces the idea that sensitive data is likely being handled with appropriate safeguards. However, there are areas for improvement. A significant concern is the relatively low percentage of SQL queries using prepared statements (34%) and output escaping (29%). This suggests a potential for SQL injection and cross-site scripting (XSS) vulnerabilities, respectively, especially in the numerous SQL queries and output operations present. The presence of capability checks (0) is also notable; while there are no unprotected entry points, robust capability checks on AJAX handlers could further harden the plugin against privilege escalation or unauthorized access attempts.
In conclusion, the plugin's lack of historical vulnerabilities and a small, protected attack surface are commendable strengths. Nevertheless, the static analysis reveals clear areas of concern regarding data sanitization and validation, particularly for SQL queries and output. Addressing these would significantly enhance the plugin's security, moving it from a "good" to an "excellent" security standing.
Key Concerns
- Low percentage of SQL queries using prepared statements
- Low percentage of properly escaped output
- No capability checks on AJAX handlers
Vandar.io Gravityform Security Vulnerabilities
Vandar.io Gravityform Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Vandar.io Gravityform Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
Vandar.io Gravityform Maintenance & Trust
Maintenance Signals
Community Trust
Vandar.io Gravityform Alternatives
Razorpay for Gravity Forms
razorpay-gravity-forms
Allows you to use Razorpay payment gateway with the gravity forms plugin.
Zibal Payment Gateway for Gravity Forms
zibal-payment-gateway-for-gravity-forms
با نصب این پلاگین می توانید از خدمات درگاه پرداخت واسط و مستقیم و یا اختصاصی زیبال برروی افزونه گرویتی فرم استفاده کنید!
Paystack Add-On for Gravity Forms
paystack-add-on-for-gravity-forms
The Paystack Addon for Gravity Forms allows you to quickly and easily implement credit card payments with WordPress. With the Paystack Add-On you can …
Pronamic Pay with Mollie for Gravity Forms
pronamic-pay-with-mollie-for-gravity-forms
Connect Mollie to Gravity Forms with Pronamic Pay. This free plugin is all that you need to start selling with Gravity Forms.
Cashfree Gravity Forms
cashfree-gravity-forms
Allows you to use Cashfree payment gateway with the gravity forms plugin.
Vandar.io Gravityform Developer Profile
4 plugins · 120 total installs
How We Detect Vandar.io Gravityform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vandar-gravityform/assets/css/admin.css/wp-content/plugins/vandar-gravityform/assets/css/vandar.css/wp-content/plugins/vandar-gravityform/assets/js/shamsi_chart.js/wp-content/plugins/vandar-gravityform/assets/js/vandar.js/wp-content/plugins/vandar-gravityform/assets/js/shamsi_chart.js/wp-content/plugins/vandar-gravityform/assets/js/vandar.jsvandar-gravityform/assets/css/admin.css?ver=vandar-gravityform/assets/css/vandar.css?ver=vandar-gravityform/assets/js/shamsi_chart.js?ver=vandar-gravityform/assets/js/vandar.js?ver=HTML / DOM Fingerprints
vandar_graph_containervandar_message_containervandar_summary_containervandar_summary_itemvandar_summary_valuevandar_summary_titletooltipbox_bluetooltipbox_green+2 more<!-- ------------------------GravityForms.IR------------------------- -->gf_vandar_chartGFPersian_paymentsrgget