
Zola CRM Add-on for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/zola-crm-add-on-for-gravity-formsAdd-on for Gravity Forms to submit leads data to Zola CRM.
Is Zola CRM Add-on for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 85/100Zola CRM Add-on for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "zola-crm-add-on-for-gravity-forms" v1.3.4 reveals a generally strong security posture. The plugin demonstrates excellent practices by having zero unprotected entry points, no dangerous functions, and exclusively using prepared statements for SQL queries. All output is properly escaped, and there are no file operations or unsanitized paths identified in the taint analysis. The absence of known CVEs and a clean vulnerability history further bolster this positive assessment. However, a few areas warrant attention. The presence of a single external HTTP request without further details about its handling is a minor concern. More significantly, the complete lack of nonce checks and capability checks across all code, coupled with zero AJAX handlers and REST API routes, suggests a potential blind spot. While the current attack surface is zero, any future addition of these elements without proper security checks could introduce vulnerabilities. In conclusion, the plugin is currently in a very secure state with strong coding practices. The primary weakness lies in the absence of security checks like nonces and capability checks, which, while not posing an immediate threat given the current limited entry points, represent a potential risk if the plugin evolves.
Key Concerns
- No Nonce Checks
- No Capability Checks
- External HTTP request without auth/validation
Zola CRM Add-on for Gravity Forms Security Vulnerabilities
Zola CRM Add-on for Gravity Forms Code Analysis
Output Escaping
Zola CRM Add-on for Gravity Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Zola CRM Add-on for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Zola CRM Add-on for Gravity Forms Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
Zola CRM Add-on for Gravity Forms Developer Profile
1 plugin · 70 total installs
How We Detect Zola CRM Add-on for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zola-crm-add-on-for-gravity-forms/store_referrer.js/wp-content/plugins/zola-crm-add-on-for-gravity-forms/store_referrer.jsHTML / DOM Fingerprints
zs_store_referrer