Chargely Free Subscriptions For Woocommernce Security & Risk Analysis

wordpress.org/plugins/chargely-free-subscriptions-for-woocommerce

Start your Subscription Business in minutes with Chargely. Chargely provides PCI Certified Payment page for your card processing. So that you don't need a PCI Certification.

0 active installs v1.0 PHP 7.2+ WP 5.9+ Updated May 20, 2023
paymentpaypalrecurring-paymentsstripesubscriptions
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chargely Free Subscriptions For Woocommernce Safe to Use in 2026?

Generally Safe

Score 85/100

Chargely Free Subscriptions For Woocommernce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "chargely-free-subscriptions-for-woocommerce" v1.0 exhibits significant security concerns despite having no recorded historical vulnerabilities. The static analysis reveals a substantial attack surface with all three identified entry points (2 AJAX handlers and 1 REST API route) lacking necessary authentication or permission checks. This is a critical weakness, as it means any unauthenticated user could potentially trigger these functions.

Taint analysis indicates a high-severity flow with unsanitized input, which, when combined with the unprotected entry points, presents a tangible risk of injection attacks or other vulnerabilities. While the plugin largely uses prepared statements for SQL queries and has a good proportion of output escaping, the lack of security checks on its primary interaction points is a severe oversight. The absence of nonce checks further exacerbates the risk of CSRF attacks on the AJAX endpoints.

Given the lack of past vulnerabilities, it's difficult to ascertain a long-term security pattern. However, the current version demonstrates concerning development practices regarding input validation and access control on its exposed functionality. The strengths lie in its SQL query preparation and general output escaping, but these are overshadowed by the critical flaws in its exposed interfaces. The overall security posture is weak due to the easily exploitable entry points.

Key Concerns

  • AJAX handlers without auth checks
  • REST API routes without permission callbacks
  • High severity taint flow found
  • 0 Nonce checks on entry points
  • 0 Capability checks on entry points
  • Low percentage of properly escaped output
Vulnerabilities
None known

Chargely Free Subscriptions For Woocommernce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chargely Free Subscriptions For Woocommernce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
32 prepared
Unescaped Output
117
57 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

94% prepared34 total queries

Output Escaping

33% escaped174 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<checkout> (views\frontend\checkout.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Chargely Free Subscriptions For Woocommernce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 2

authwp_ajax_myplanlibrarychargely-woocommerce.php:371
authwp_ajax_myproductlibrarychargely-woocommerce.php:442

REST API Routes 1

POST/wp-json/chargely/v1/receive-callbackchargely-woocommerce.php:479
WordPress Hooks 23
actionadmin_noticeschargely-woocommerce.php:24
actionadmin_menuchargely-woocommerce.php:50
actioninitchargely-woocommerce.php:91
actionwoocommerce_order_item_add_action_buttonschargely-woocommerce.php:93
actionplugins_loadedchargely-woocommerce.php:103
filterwoocommerce_payment_gatewayschargely-woocommerce.php:162
actionwoocommerce_admin_order_data_after_billing_addresschargely-woocommerce.php:171
actionafter_switch_themechargely-woocommerce.php:195
actioninitchargely-woocommerce.php:197
filterwoocommerce_account_menu_itemschargely-woocommerce.php:202
actionwoocommerce_account_chargely-subscriptions_endpointchargely-woocommerce.php:211
actionwoocommerce_view_orderchargely-woocommerce.php:216
actionafter_woocommerce_paychargely-woocommerce.php:221
actionwoocommerce_after_add_to_cart_buttonchargely-woocommerce.php:229
filterwoocommerce_loop_add_to_cart_linkchargely-woocommerce.php:231
filterwoocommerce_order_button_htmlchargely-woocommerce.php:238
filterwoocommerce_add_cart_item_datachargely-woocommerce.php:244
filterwoocommerce_get_item_datachargely-woocommerce.php:269
actionwoocommerce_checkout_create_order_line_itemchargely-woocommerce.php:285
filterwoocommerce_available_payment_gatewayschargely-woocommerce.php:297
filterwoocommerce_add_cart_itemchargely-woocommerce.php:320
filterwoocommerce_get_cart_item_from_sessionchargely-woocommerce.php:321
actionrest_api_initchargely-woocommerce.php:476
Maintenance & Trust

Chargely Free Subscriptions For Woocommernce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 20, 2023
PHP min version7.2
Downloads878

Community Trust

Rating20/100
Number of ratings1
Active installs0
Developer Profile

Chargely Free Subscriptions For Woocommernce Developer Profile

chargely

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chargely Free Subscriptions For Woocommernce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/css/jquery.dataTables.min.css/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/css/jquery.notifyBar.css/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/css/mystyle.css/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/jquery.validate.min.js/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/jquery.dataTables.min.js/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/jquery.notifyBar.js/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/myscript.js
Script Paths
/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/jquery.validate.min.js/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/jquery.dataTables.min.js/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/jquery.notifyBar.js/wp-content/plugins/chargely-free-subscriptions-for-woocommerce/js/myscript.js

HTML / DOM Fingerprints

CSS Classes
chargely-woocommerce-plugin
Data Attributes
data-chargely-url
JS Globals
myplanajaxurl
FAQ

Frequently Asked Questions about Chargely Free Subscriptions For Woocommernce