Buy Now Plus — Payments with Stripe Security & Risk Analysis

wordpress.org/plugins/buy-now-plus

A cloud-backed plugin that lets you securely accept Credit Card payments on your site using Stripe without needing to install an SSL certificate.

20 active installs v1.0.4 PHP + WP 6.0+ Updated Feb 2, 2026
buy-nowcredit-cardecommercepaymentsstripe
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 27, 2026
Safety Verdict

Is Buy Now Plus — Payments with Stripe Safe to Use in 2026?

Generally Safe

Score 99/100

Buy Now Plus — Payments with Stripe has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 27, 2026Updated 2mo ago
Risk Assessment

The 'buy-now-plus' v1.0.4 plugin demonstrates a generally strong security posture based on the static analysis provided. The absence of dangerous functions, raw SQL queries, and unsanitized taint flows is highly positive. All identified output is properly escaped, and file operations are not present, further reducing the attack surface. The plugin also correctly implements nonce and capability checks for its entry points, and its REST API is securely configured. The small number of entry points, all of which are protected, indicates a focused and well-secured design.

However, the presence of two external HTTP requests without further context raises a minor concern. While not explicitly flagged as a vulnerability, uncontrolled external requests can sometimes lead to issues like SSRF or reliance on vulnerable external services. The vulnerability history reveals one past CVE, a Cross-site Scripting vulnerability, which was resolved. While there are no currently unpatched vulnerabilities, the past occurrence of XSS suggests that vigilance is still warranted, especially as new versions are developed. The plugin's strength lies in its secure coding practices for direct interactions, but external dependencies should be monitored.

In conclusion, 'buy-now-plus' v1.0.4 appears to be a reasonably secure plugin with good adherence to core WordPress security best practices. The static analysis is largely reassuring. The main area for continued attention would be the security implications of its external HTTP requests and ensuring any future vulnerabilities are promptly addressed, as indicated by its past CVE. Overall, it presents a low to moderate risk.

Key Concerns

  • External HTTP requests present
  • Past XSS vulnerability recorded
Vulnerabilities
1

Buy Now Plus — Payments with Stripe Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1295medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Buy Now Plus <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Jan 27, 2026 Patched in 1.0.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

Buy Now Plus — Payments with Stripe Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Buy Now Plus — Payments with Stripe Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_bnp_query_buttonsclass-bnp-editor.php:13

Shortcodes 1

[buynowplus] class-bnp-buttons.php:7
WordPress Hooks 7
actionwp_enqueue_scriptsclass-bnp-buttons.php:6
actionadmin_initclass-bnp-editor.php:7
actionadmin_enqueue_scriptsclass-bnp-editor.php:10
filtermce_external_pluginsclass-bnp-editor.php:29
filtermce_buttonsclass-bnp-editor.php:30
actionadmin_menuclass-bnp-settings.php:6
actionadmin_enqueue_scriptsclass-bnp-settings.php:7
Maintenance & Trust

Buy Now Plus — Payments with Stripe Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version
Downloads4K

Community Trust

Rating70/100
Number of ratings4
Active installs20
Developer Profile

Buy Now Plus — Payments with Stripe Developer Profile

Blair Williams

4 plugins · 630K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
1044 days
View full developer profile
Detection Fingerprints

How We Detect Buy Now Plus — Payments with Stripe

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buy-now-plus/css/buynowplus.css
Version Parameters
buy-now-plus/css/buynowplus.css?ver=1.0.4

HTML / DOM Fingerprints

CSS Classes
buy-now
Data Attributes
id="buy-now-title="Buy Now"
Shortcode Output
<a id="buy-now-buy-nowplus
FAQ

Frequently Asked Questions about Buy Now Plus — Payments with Stripe