WCC GF – Lawmatics Security & Risk Analysis

wordpress.org/plugins/wcc-gf-to-lawmatics

Send Gravity Form Plugin Submissions to Lawmatics.

0 active installs v1.1.0 PHP 7.2+ WP 4.7+ Updated Mar 11, 2025
gravity-form-lawmaticsgravity-form-lawmatics-web-to-leadlawmaticswordpress-lawmaticswordpress-lawmatics-integration
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WCC GF – Lawmatics Safe to Use in 2026?

Generally Safe

Score 92/100

WCC GF – Lawmatics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The wcc-gf-to-lawmatics plugin version 1.1.0 exhibits a generally strong security posture with a focus on secure coding practices. The static analysis reveals no critical or high severity issues in taint flows, and SQL queries are exclusively executed using prepared statements. A high percentage of output is properly escaped, and there is a significant number of nonce checks, indicating an effort to protect against common WordPress vulnerabilities. The plugin's attack surface is also well-protected, with all identified entry points appearing to have authentication checks. Furthermore, the absence of any known CVEs, past or present, suggests a history of secure development and maintenance.

Despite these strengths, there are a few areas that warrant attention. The presence of four flows with unsanitized paths in the taint analysis, even if not rated as critical or high, indicates potential for unexpected behavior or manipulation if certain inputs are not thoroughly validated. Additionally, the plugin performs external HTTP requests, which, if not handled with extreme care, could expose the site to risks from compromised external services. While the plugin has no recorded vulnerability history, this can also mean limited exposure or testing in diverse environments. Overall, the plugin demonstrates good foundational security, but the taint flow findings and external requests suggest the need for continued vigilance and thorough testing of specific input handling scenarios.

Key Concerns

  • Flows with unsanitized paths (4)
  • External HTTP requests (5)
Vulnerabilities
None known

WCC GF – Lawmatics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WCC GF – Lawmatics Release Timeline

v1.2.0
v1.1.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

WCC GF – Lawmatics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
65 prepared
Unescaped Output
13
527 escaped
Nonce Checks
22
Capability Checks
0
File Operations
1
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared65 total queries

Output Escaping

98% escaped540 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

11 flows4 with unsanitized paths
wcc_gf_lawmatics_get_module_fields (Inc/WccGfLawmatics_Actions.php:125)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WCC GF – Lawmatics Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

noprivwp_ajax_wcc_gf_lawmatics_get_module_fieldsInc/WccGfLawmatics_Actions.php:58
authwp_ajax_wcc_gf_lawmatics_get_module_fieldsInc/WccGfLawmatics_Actions.php:59
noprivwp_ajax_wcc_gf_lawmatics_get_module_fields_and_form_fieldInc/WccGfLawmatics_Actions.php:62
authwp_ajax_wcc_gf_lawmatics_get_module_fields_and_form_fieldInc/WccGfLawmatics_Actions.php:63
noprivwp_ajax_wcc_gf_lawmatics_statusInc/WccGfLawmatics_Actions.php:65
authwp_ajax_wcc_gf_lawmatics_statusInc/WccGfLawmatics_Actions.php:67
WordPress Hooks 7
actioninitInc/WccGfLawmatics_Actions.php:37
actionadmin_enqueue_scriptsInc/WccGfLawmatics_Actions.php:43
actionadmin_menuInc/WccGfLawmatics_Actions.php:45
actionadmin_menuInc/WccGfLawmatics_Actions.php:46
actionwcc_entries_form_gform_submit_actionInc/WccGfLawmatics_Actions.php:51
actiongform_after_submissionInc/WccGfLawmatics_Actions.php:53
actionwcc_entries_below_view_page_leftInc/WccGfLawmatics_Actions.php:69
Maintenance & Trust

WCC GF – Lawmatics Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 11, 2025
PHP min version7.2
Downloads813

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

WCC GF – Lawmatics Developer Profile

weconnectcodeplugins

13 plugins · 10 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WCC GF – Lawmatics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wcc-gf-to-lawmatics/assets/css/wcc-gf-lawmatics-admin.css/wp-content/plugins/wcc-gf-to-lawmatics/assets/css/wcc-gf-lawmatics-frontend.css/wp-content/plugins/wcc-gf-to-lawmatics/assets/js/wcc-gf-lawmatics-admin.js/wp-content/plugins/wcc-gf-to-lawmatics/assets/js/wcc-gf-lawmatics-frontend.js
Script Paths
/wp-content/plugins/wcc-gf-to-lawmatics/assets/js/wcc-gf-lawmatics-admin.js/wp-content/plugins/wcc-gf-to-lawmatics/assets/js/wcc-gf-lawmatics-frontend.js
Version Parameters
wcc-gf-to-lawmatics/assets/css/wcc-gf-lawmatics-admin.css?ver=wcc-gf-to-lawmatics/assets/css/wcc-gf-lawmatics-frontend.css?ver=wcc-gf-to-lawmatics/assets/js/wcc-gf-lawmatics-admin.js?ver=wcc-gf-to-lawmatics/assets/js/wcc-gf-lawmatics-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcc-gf-lawmatics-settings
HTML Comments
<!-- wcc_gf_lawmatics_shortcode --><!-- Start wcc_gf_lawmatics_shortcode --><!-- End wcc_gf_lawmatics_shortcode --><!-- Plugin Name: WCC GF to Lawmatics -->+2 more
Data Attributes
data-wcc-gf-lawmatics-nonce
JS Globals
wcc_gf_lawmatics_ajax_objectwcc_gf_lawmatics_vars
Shortcode Output
[wcc_gf_lawmatics_shortcode]
FAQ

Frequently Asked Questions about WCC GF – Lawmatics