
Buy Now Plus — Payments with Stripe Security & Risk Analysis
wordpress.org/plugins/buy-now-plusA cloud-backed plugin that lets you securely accept Credit Card payments on your site using Stripe without needing to install an SSL certificate.
Is Buy Now Plus — Payments with Stripe Safe to Use in 2026?
Generally Safe
Score 99/100Buy Now Plus — Payments with Stripe has a strong security track record. Known vulnerabilities have been patched promptly.
The 'buy-now-plus' v1.0.4 plugin demonstrates a generally strong security posture based on the static analysis provided. The absence of dangerous functions, raw SQL queries, and unsanitized taint flows is highly positive. All identified output is properly escaped, and file operations are not present, further reducing the attack surface. The plugin also correctly implements nonce and capability checks for its entry points, and its REST API is securely configured. The small number of entry points, all of which are protected, indicates a focused and well-secured design.
However, the presence of two external HTTP requests without further context raises a minor concern. While not explicitly flagged as a vulnerability, uncontrolled external requests can sometimes lead to issues like SSRF or reliance on vulnerable external services. The vulnerability history reveals one past CVE, a Cross-site Scripting vulnerability, which was resolved. While there are no currently unpatched vulnerabilities, the past occurrence of XSS suggests that vigilance is still warranted, especially as new versions are developed. The plugin's strength lies in its secure coding practices for direct interactions, but external dependencies should be monitored.
In conclusion, 'buy-now-plus' v1.0.4 appears to be a reasonably secure plugin with good adherence to core WordPress security best practices. The static analysis is largely reassuring. The main area for continued attention would be the security implications of its external HTTP requests and ensuring any future vulnerabilities are promptly addressed, as indicated by its past CVE. Overall, it presents a low to moderate risk.
Key Concerns
- External HTTP requests present
- Past XSS vulnerability recorded
Buy Now Plus — Payments with Stripe Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Buy Now Plus <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Buy Now Plus — Payments with Stripe Code Analysis
Output Escaping
Buy Now Plus — Payments with Stripe Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Buy Now Plus — Payments with Stripe Maintenance & Trust
Maintenance Signals
Community Trust
Buy Now Plus — Payments with Stripe Alternatives
Contact Form 7 – PayPal & Stripe Add-on
contact-form-7-paypal-add-on
Easily add PayPal and Stripe to Contact Form 7. Accept credit card payments with Stripe & PayPal on your site today. Offical PayPal & Stripe Partner.
WP Stripe Checkout
wp-stripe-checkout
Accept Stripe payments in WordPress without creating any product. Perfect for donations, services, or selling anything. No coding required.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
WooCommerce Stripe Payment Gateway
woocommerce-gateway-stripe
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
Buy Now Plus — Payments with Stripe Developer Profile
4 plugins · 630K total installs
How We Detect Buy Now Plus — Payments with Stripe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buy-now-plus/css/buynowplus.cssbuy-now-plus/css/buynowplus.css?ver=1.0.4HTML / DOM Fingerprints
buy-nowid="buy-now-title="Buy Now"<a id="buy-now-buy-nowplus