Gravity Forms Debug Add-On
Plugin
by rocketgenius
·
meteorgpl-plugin/gravityformsdebug
·
latest 1.0.beta12,
Install
Install with Composer
composer require meteorgpl-plugin/gravityformsdebug
Register the repository once per project: composer config repositories.meteorgpl composer https://composer.meteorgpl.com
Add to composer.json
"meteorgpl-plugin/gravityformsdebug": "^1.0"
The example composer.json shows the repository and installer-paths blocks.
Store your token
composer config --global http-basic.composer.meteorgpl.com token <your-token>
Create tokens on your tokens page; in CI use COMPOSER_AUTH.
Overview
All 1 published version passed every check
Each version is cleaned, compared against the vendor’s license code and scanned before it is committed. A version that does not pass is not published. Last scan .
Held back: archives of this plugin that did not pass the automatic checks and are not published. Findings reviewed: matches of the rules that were checked and resolved before publication.
How every version is checked
Malware scan ClamAV 1.5.4, signature database 28145 (2026-10-06)
Every file of every version against the ClamAV signature database.
Pattern rules YARA 4.5.2 · project.yar, php.yar · rule set 7bc5d96c5835
Web shells, obfuscated loaders, encoded PHP and known nulling patterns (php-malware-finder plus MeteorGPL rules).
PHP analysis Heuristics v8
Token-level analysis: remote includes, request input reaching shell functions, decoders feeding eval, PHP hidden in images, fonts or archives, server handler overrides.
License integrity Signature set 2684332b10b3
License, activation and update code is compared with the vendor’s own code and the previous version; altered license code is never published.
PHP syntax PHP 8.3.33
Every PHP file parses on the PHP version the repository supports.
Asset policy 0 images replaced · 0 files removed
Artwork, fonts, media and demo content that may be licensed separately are replaced with placeholders or removed (license profile gpl-full).
Scans per version
| Version | Scanned | Files | ClamAV signatures | Findings reviewed | Assets replaced | Duration | Result |
|---|---|---|---|---|---|---|---|
| 1.0.beta12 | 4 | 28145 (2026-10-06) | 0 | 0 | 0.4 s | Verified |
Security policy
Reporting a vulnerability. Security problems in the plugin’s own code belong to the vendor, rocketgenius; report them there. Problems with a package as this repository distributes it — a file that should not be there, a scan that missed something — go to packages@meteorgpl.com, and are answered within 48 hours.
What happens on a finding. The affected versions are withdrawn from the repository, watchers of the package are notified, and a corrected version is published when one passes every check.
Rights holders. The takedown policy describes how a package is removed.
Known vulnerabilities
Vulnerability monitoring is not active yet
Public vulnerability reports are not checked for this package yet, so none are listed here.