CTCL Stripe Security & Risk Analysis

wordpress.org/plugins/ctcl-stripe

Accept Stripe Payment with CT Commerce Lite ecommerce platform.

0 active installs v1.2.2 PHP + WP + Updated Jul 4, 2025
ct-commerce-liteecommercepayment-gatewaystripe
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CTCL Stripe Safe to Use in 2026?

Generally Safe

Score 100/100

CTCL Stripe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The plugin "ctcl-stripe" v1.2.2 presents a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no instances of dangerous functions, file operations, external HTTP requests, or known vulnerability history. This indicates a well-contained plugin with no readily exploitable entry points and no prior security incidents.

However, a significant concern emerges from the output escaping analysis, where 100% of identified outputs are not properly escaped. This means that data displayed by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sanitized before being rendered. Additionally, the absence of nonce checks and capability checks, while not directly indicative of a vulnerability given the zero attack surface, suggests a lack of robust authorization and integrity checks that would be crucial if any new entry points were introduced in future versions.

While the plugin benefits from the absence of known vulnerabilities and a clean taint analysis, the unescaped output is a critical oversight that exposes users to a common and potentially severe attack vector. The bundled Stripe PHP library is a strength, assuming it is kept up-to-date, but it does not mitigate the immediate output escaping risk. The overall security is commendable in its limited scope, but the unescaped output significantly lowers its reliability.

Key Concerns

  • 0% of output properly escaped
Vulnerabilities
None known

CTCL Stripe Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CTCL Stripe Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Stripe PHP

Output Escaping

0% escaped1 total outputs
Attack Surface

CTCL Stripe Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterctcl_payment_optionsctcl-stripe.php:89
actionwp_enqueue_scriptsctcl-stripe.php:105
actionwp_enqueue_scriptsctcl-stripe.php:106
filterctcl_admin_billings_htmlctcl-stripe.php:134
actionadmin_noticesctcl-stripe.php:223
Maintenance & Trust

CTCL Stripe Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 4, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CTCL Stripe Developer Profile

UjW0L

17 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CTCL Stripe

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ctcl-stripe/css/ctcl_stripe.css
Script Paths
https://js.stripe.com/v3/

HTML / DOM Fingerprints

CSS Classes
ctcl-stripe-settingsctcl-stripe-display-label-labelctc-stripe-test-publishable-key-labelctc-stripe-test-secret-key-labelctcl-stripe-test-mode-labelctc-stripe-live-publishable-key-labelctc-stripe-live-secret-key-label
Data Attributes
id='ctcl-activate-stripe'id='ctcl-stripe-display-label'id='ctc-stripe-test-publishable-key'id='ctc-stripe-test-secret-key'id='ctcl-stripe-test-mode'id='ctc-stripe-live-publishable-key'
JS Globals
ctclStripeParams
FAQ

Frequently Asked Questions about CTCL Stripe