
Click & Pledge – Paid Memberships Pro Security & Risk Analysis
wordpress.org/plugins/click-pledge-paid-memberships-proClick & Pledge payment gateway integration for Paid Memberships Pro with Salesforce support.
Is Click & Pledge – Paid Memberships Pro Safe to Use in 2026?
Generally Safe
Score 100/100Click & Pledge – Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "click-pledge-paid-memberships-pro" plugin v25.12000000-WP6.9-PMP3.6.3 exhibits a concerning security posture due to a significant number of unprotected entry points. The static analysis reveals 8 AJAX handlers, all of which lack authentication checks, exposing a substantial attack surface to unauthenticated users. This is further compounded by the presence of the dangerous `unserialize` function, which can lead to remote code execution if improperly handled with untrusted input. While the plugin demonstrates good practices in SQL query preparation (95% prepared) and output escaping (92% escaped), the lack of basic security checks on AJAX endpoints and the potential risk from `unserialize` outweigh these strengths. The absence of any recorded vulnerabilities in its history might suggest a lack of widespread exploitation or an assumption of security, but it does not negate the risks identified in the code. The plugin's overall security is weakened by these identified weaknesses, requiring immediate attention.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function 'unserialize' found
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
- Flows with unsanitized paths found
Click & Pledge – Paid Memberships Pro Security Vulnerabilities
Click & Pledge – Paid Memberships Pro Release Timeline
Click & Pledge – Paid Memberships Pro Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Click & Pledge – Paid Memberships Pro Attack Surface
AJAX Handlers 8
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Click & Pledge – Paid Memberships Pro Maintenance & Trust
Maintenance Signals
Community Trust
Click & Pledge – Paid Memberships Pro Alternatives
Click & Pledge WPJobBoard
click-pledge-wpjobboard
Click & Pledge payment gateway integration for WPJobBoard with Salesforce support.
Click & Pledge for Gravity Forms
gravity-forms-click-pledge
Add a credit card payment gateway for Click & Pledge to the Gravity Forms plugin
Voguepay plugin for Paid Memberships Pro
pmpro-voguepay
This plugin allows you to accept payment from local and international customers on Paid Memberships Pro.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Click & Pledge – Paid Memberships Pro Developer Profile
5 plugins · 200 total installs
How We Detect Click & Pledge – Paid Memberships Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-pledge-paid-memberships-pro/css/pmpro-click-pledge.css/wp-content/plugins/click-pledge-paid-memberships-pro/js/pmpro-click-pledge.js/wp-content/plugins/click-pledge-paid-memberships-pro/js/pmpro-click-pledge.jsclick-pledge-paid-memberships-pro/css/pmpro-click-pledge.css?ver=click-pledge-paid-memberships-pro/js/pmpro-click-pledge.js?ver=HTML / DOM Fingerprints
pmpro_card_fieldspmpro_click_pledge_params