
CollabPay ‑ Split Profits Security & Risk Analysis
wordpress.org/plugins/collabpayAutomatically calculate, split & pay profits to product creators, influencers or sales reps!
Is CollabPay ‑ Split Profits Safe to Use in 2026?
Generally Safe
Score 92/100CollabPay ‑ Split Profits has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The CollabPay plugin v1.9.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has a relatively small attack surface with all identified entry points (REST API routes) seemingly protected by permission callbacks. Furthermore, the absence of dangerous functions, file operations, and known vulnerabilities in its history are positive indicators. However, there are significant areas for concern. The plugin's SQL queries are not using prepared statements, presenting a potential risk for SQL injection vulnerabilities, especially if any of the query parameters are derived from user input. Additionally, the lack of nonce checks and capability checks, while not directly linked to an exploit path in the provided data, represents a missed opportunity to implement standard WordPress security practices and could be exploited in conjunction with other vulnerabilities if they were to arise.
Key Concerns
- SQL queries without prepared statements
- Zero nonce checks implemented
- Zero capability checks implemented
- 77% of output escaping is good, but 23% is not
CollabPay ‑ Split Profits Security Vulnerabilities
CollabPay ‑ Split Profits Release Timeline
CollabPay ‑ Split Profits Code Analysis
SQL Query Safety
Output Escaping
CollabPay ‑ Split Profits Attack Surface
REST API Routes 5
WordPress Hooks 18
Maintenance & Trust
CollabPay ‑ Split Profits Maintenance & Trust
Maintenance Signals
Community Trust
CollabPay ‑ Split Profits Alternatives
Netgíró Payment Gateway for WooCommerce
netgiro-payment-gateway-for-woocommerce
Offer your customers Netgíró’s quick, secure, and streamlined payment solution directly in your WooCommerce store.
Split Pay – Stripe Connect Split Payments & Multi-Vendor Marketplace for WooCommerce
bsd-woo-stripe-connect-split-pay
Split payments made in WooCommerce stores between multiple Stripe Connected Accounts and a Stripe Platform Account.
Limepay WooCommerce Gateway
limepay-woocommerce-gateway
Woo-Commerce gateway extension to support Limepay payments
April Payment Gateway for WooCommerce
april-payment-gateway-for-woocommerce
Woo-Commerce gateway extension to support April payments
LoyCart-POS
loycart-pos
LoyCart-POS provides a simple, fast, accurate, and seamless point-of-sale interface directly within your WordPress admin dashboard.
CollabPay ‑ Split Profits Developer Profile
1 plugin · 40 total installs
How We Detect CollabPay ‑ Split Profits
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/collabpay/assets/css/collabpay-backend.css/wp-content/plugins/collabpay/assets/js/collabpay-backend.js/wp-content/plugins/collabpay/assets/js/collabpay-backend.jscollabpay/assets/css/collabpay-backend.css?ver=collabpay/assets/js/collabpay-backend.js?ver=HTML / DOM Fingerprints
name="_collabpay_cost[id="_collabpay_costwindow.cp_ref/wp-json/collabpay/v1/ping/wp-json/collabpay/v1/webhooks/deactivate/wp-json/collabpay/v1/webhooks/activate/wp-json/collabpay/v1/revoke/wp-json/collabpay/v1/refunds