WCC GF to Brevo Security & Risk Analysis

wordpress.org/plugins/wcc-gf-to-brevo

Send Gravity Form Plugin Submissions to Brevo.

0 active installs v1.0.0 PHP 7.2+ WP 4.7+ Updated Sep 16, 2025
brevogravity-form-brevogravity-form-brevo-web-to-leadwordpress-brevowordpress-brevo-integration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WCC GF to Brevo Safe to Use in 2026?

Generally Safe

Score 100/100

WCC GF to Brevo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "wcc-gf-to-brevo" plugin v1.0.0 demonstrates a generally good security posture with strong adherence to secure coding practices. The plugin effectively utilizes prepared statements for nearly all SQL queries and ensures a high percentage of output is properly escaped, significantly mitigating common web vulnerabilities like SQL injection and cross-site scripting. The presence of numerous nonce and capability checks on its AJAX handlers further suggests a conscious effort to protect these entry points from unauthorized access.

However, the static analysis did reveal one concerning taint flow with a high severity. While the exact nature isn't detailed, a single high-severity unsanitized path in a taint flow warrants attention, as it could potentially lead to an exploitable vulnerability if the input is user-controlled and not adequately handled downstream. The presence of file operations and external HTTP requests, while not inherently insecure, always represent potential attack vectors that require careful scrutiny. The plugin's vulnerability history is clean, indicating a lack of previously discovered public vulnerabilities, which is a positive sign.

In conclusion, "wcc-gf-to-brevo" v1.0.0 is built on a solid foundation of secure coding practices. The primary area of concern stems from the single high-severity taint flow. Addressing this specific flow and ensuring robust input validation and sanitization for any sensitive operations, especially those involving file interactions or external requests, would further enhance its security.

Key Concerns

  • High severity taint flow
Vulnerabilities
None known

WCC GF to Brevo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WCC GF to Brevo Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
88 prepared
Unescaped Output
10
420 escaped
Nonce Checks
25
Capability Checks
0
File Operations
1
External Requests
4
Bundled Libraries
0

SQL Query Safety

91% prepared97 total queries

Output Escaping

98% escaped430 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

9 flows1 with unsanitized paths
wcc_gf_brevo_get_module_fields (Inc\WccGfBrevo_Actions.php:125)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WCC GF to Brevo Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

noprivwp_ajax_wcc_gf_brevo_get_module_fieldsInc\WccGfBrevo_Actions.php:57
authwp_ajax_wcc_gf_brevo_get_module_fieldsInc\WccGfBrevo_Actions.php:58
noprivwp_ajax_wcc_gf_brevo_get_module_fields_and_form_fieldInc\WccGfBrevo_Actions.php:61
authwp_ajax_wcc_gf_brevo_get_module_fields_and_form_fieldInc\WccGfBrevo_Actions.php:62
noprivwp_ajax_wcc_gf_brevo_statusInc\WccGfBrevo_Actions.php:64
authwp_ajax_wcc_gf_brevo_statusInc\WccGfBrevo_Actions.php:66
WordPress Hooks 7
actioninitInc\WccGfBrevo_Actions.php:37
actionadmin_enqueue_scriptsInc\WccGfBrevo_Actions.php:41
actionadmin_menuInc\WccGfBrevo_Actions.php:43
actionadmin_menuInc\WccGfBrevo_Actions.php:44
actionwcc_entries_form_gform_submit_actionInc\WccGfBrevo_Actions.php:50
actiongform_after_submissionInc\WccGfBrevo_Actions.php:52
actionwcc_entries_below_view_page_leftInc\WccGfBrevo_Actions.php:68
Maintenance & Trust

WCC GF to Brevo Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version7.2
Downloads154

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WCC GF to Brevo Developer Profile

weconnectcodeplugins

11 plugins · 10 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WCC GF to Brevo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wcc-gf-to-brevo/assets/css/wcc-gf-to-brevo-admin.css/wp-content/plugins/wcc-gf-to-brevo/assets/js/wcc-gf-to-brevo-admin.js/wp-content/plugins/wcc-gf-to-brevo/assets/js/wcc-gf-to-brevo.js
Version Parameters
wcc-gf-to-brevo/assets/css/wcc-gf-to-brevo-admin.css?ver=wcc-gf-to-brevo/assets/js/wcc-gf-to-brevo-admin.js?ver=wcc-gf-to-brevo/assets/js/wcc-gf-to-brevo.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcc-gf-brevo-settings
Data Attributes
data-wcc-gf-brevo-form-iddata-wcc-gf-brevo-feed-id
JS Globals
wcc_gf_brevo_ajax_object
Shortcode Output
[wcc_gf_brevo_shortcode]
FAQ

Frequently Asked Questions about WCC GF to Brevo