In my last blog, I wrote about the archaic nature of law firm WordPress websites and how they are increasingly vulnerable to cybersecurity threats. If your firm is on WordPress, there is no need to abandon the platform, but it's likely you have some cleanup to do.

The number of competent WordPress developers is actually very small and most of the law firm builds I have seen hack together 20 or more random plugins to accommodate the engineering shortcomings of the developer. They almost all have out-of-date plugins and the unique combination of plugins they use often prevents proper WordPress updates without breaking the theme.

The ethics rule you may be breaking

In the age of AI, firms should be paying special attention to ABA Ethics Opinion 477R, especially as it pertains to Gravity Forms and out-of-date self-hosted contact form plugins.

Ethics Opinion 477R states:

A lawyer generally may transmit information relating to the representation of a client over the internet without violating the Model Rules of Professional Conduct where the lawyer has undertaken reasonable efforts to prevent inadvertent or unauthorized access. However, a lawyer may be required to take special security precautions to protect against the inadvertent or unauthorized disclosure of client information when required by an agreement with the client or by law, or when the nature of the information requires a higher degree of security.

This ruling updates Model Rule 1.6(c) of the ABA Model Rules of Professional Conduct, which requires lawyers to make "reasonable efforts" to prevent unauthorized access to or disclosure of client information.

Firms are required to keep software updated and to protect client information, which are two basic pillars almost no one is following thanks to the cumbersome nature of WordPress.

The intake time bomb

If your developer cobbled together a site using all sorts of questionable plugins, you are sitting on a ticking time bomb and nowhere is the issue more grave than with intake.

Gravity Forms is a contact form plugin built for WordPress that is ubiquitous among retail firms. This is the software that drives intake for most injury and bankruptcy firms, but it's self-hosted.

All of the details clients enter about themselves and their matter, which often include sensitive financial and health-related information, are just sitting there in the database. In my experience, there is very rarely encryption and in many cases, years of client contact are stored directly inside out-of-date WordPress themes, some of which are frozen in time due to sloppy builds that can't work with the newest WordPress versions.

As I mentioned above, because of the reliance on bulky plugins to build these sites, it's never a guarantee that Gravity Forms can be kept up to date without breaking the rest of the site.

Abandoned add-ons are open doors

Gravity Forms has all sorts of abandoned add-ons that are no longer central to the software, but still live on their users' sites. Gravity Forms introduced its Add-On Framework and then rewrote the form editor and output markup in the 2.5 version. Anything written against the pre-framework API is outdated. The Gravity Forms team moved on years ago; there's no update coming.

These old products are literal welcome signs for malicious actors.

Further, when a license expires, the form doesn't stop working, it just stops receiving security updates. That, and notices from Gravity Forms, are easy to miss because Gravity Forms notifications ride on whatever PHP mail or SMTP configuration the host happens to have, which is how intake silently vanishes into spam folders.

What to do about it

There is no SOC 2 compliance, it's just a blob of vulnerable code soaking up years of sensitive client information. There is nothing wrong with using Gravity Forms if there is a dedicated team member who owns keeping it up to date and retiring unnecessary legacy code, plus storing client intake information in a more secure place. So, if you can eagle-eye your site and maintain great WordPress hygiene, great, keep on using Gravity Forms. The conditional logic and ability to take payment, plus integration with CRMs, can be really useful.

However, for clients who aren't using the full feature set of Gravity Forms and who need more basic intake, I am moving firms over to a platform like Formspree that is SOC 2 compliant and which has none of the cybersecurity vulnerability of Gravity Forms. In fact, I would argue that, for most law firms, the number one thing they can do to improve security in compliance with ABA Model Rule 1.6(c) is to move from a self-hosted form like Gravity Forms to a SaaS that maintains hardened AWS infrastructure.

Is your firm using Gravity Forms for intake? Is the licensing current? Are you maintaining their old add-on products in your database unwittingly?

If you aren't sure, drop us a line, we would be happy to help.

Want this running on your firm’s site? Request access →