VIA Lead Integration for Gravity Forms and Salesforce Security & Risk Analysis

wordpress.org/plugins/via-crm-forms

VIA Lead Integration for Gravity Forms and Salesforce

0 active installs v1.0.5 PHP 7.1+ WP 5.0+ Updated Sep 1, 2020
crmgravityformsleadssalesforce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is VIA Lead Integration for Gravity Forms and Salesforce Safe to Use in 2026?

Generally Safe

Score 85/100

VIA Lead Integration for Gravity Forms and Salesforce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'via-crm-forms' plugin, version 1.0.5, exhibits a mixed security posture. On the positive side, it demonstrates good practice by exclusively using prepared statements for its SQL queries and has no recorded vulnerability history, suggesting a generally stable codebase. The absence of critical or high-severity taint flows is also encouraging, indicating that the plugin is likely not introducing severe injection vulnerabilities based on the static analysis performed.

However, the plugin presents significant security concerns due to its attack surface. All three identified AJAX handlers lack authentication checks, creating a direct entry point for unauthenticated users to interact with sensitive functionalities. Furthermore, a concerning 60% of output operations are not properly escaped. This combination of unprotected entry points and insufficient output escaping significantly increases the risk of cross-site scripting (XSS) vulnerabilities and other injection attacks. The use of the Guzzle library also warrants attention; while not inherently a vulnerability, bundled libraries can become a risk if they are outdated and contain known vulnerabilities.

In conclusion, while the plugin avoids common pitfalls like raw SQL queries and historical vulnerabilities, the lack of authentication on AJAX handlers and the prevalence of unescaped output are critical weaknesses. These issues create a substantial risk that needs to be addressed to improve the plugin's overall security. The lack of historical CVEs is a positive indicator of past development but does not mitigate the immediate risks identified in the current version's static analysis.

Key Concerns

  • AJAX handlers without authentication
  • Insufficient output escaping (40% properly escaped)
  • Bundled Guzzle library
Vulnerabilities
None known

VIA Lead Integration for Gravity Forms and Salesforce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

VIA Lead Integration for Gravity Forms and Salesforce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
9
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared3 total queries

Output Escaping

40% escaped15 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
init (src\AdminAjaxActions\FeedAction.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

VIA Lead Integration for Gravity Forms and Salesforce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_via_get_sf_field_mapsrc\AdminAjaxActions\FeedAction.php:7
authwp_ajax_via_save_sf_field_mapsrc\AdminAjaxActions\FeedAction.php:30
authwp_ajax_via_load_sf_field_mapsrc\AdminAjaxActions\SalesforceAction.php:9
WordPress Hooks 7
actionadmin_headsrc\Loader.php:22
actionadmin_noticessrc\Loader.php:33
actiongform_after_delete_formsrc\Loader.php:52
actionadmin_headsrc\Loader.php:58
actionadmin_enqueue_scriptsvia-gravityforms-salesforce.php:37
filtergform_noconflict_scriptsvia-gravityforms-salesforce.php:43
actiongform_loadedvia-gravityforms-salesforce.php:64
Maintenance & Trust

VIA Lead Integration for Gravity Forms and Salesforce Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedSep 1, 2020
PHP min version7.1
Downloads1K

Community Trust

Rating100/100
Number of ratings4
Active installs0
Developer Profile

VIA Lead Integration for Gravity Forms and Salesforce Developer Profile

viastudio

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VIA Lead Integration for Gravity Forms and Salesforce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/via-crm-forms/build/via-gravityforms.js/wp-content/plugins/via-crm-forms/build/via-gravityforms.css
Script Paths
/wp-content/plugins/via-crm-forms/build/via-gravityforms.js
Version Parameters
via-crm-forms/via-gravityforms-salesforce.php?ver=via-gravityforms-salesforce/build/via-gravityforms.js?ver=via-gravityforms-salesforce/build/via-gravityforms.css?ver=

HTML / DOM Fingerprints

CSS Classes
viagf_invalid
Data Attributes
data-gform-confirm-filter
JS Globals
gf_salesforce_addon
FAQ

Frequently Asked Questions about VIA Lead Integration for Gravity Forms and Salesforce