Responsive Pricing Table Security & Risk Analysis

wordpress.org/plugins/dk-pricr-responsive-pricing-table

A responsive and elegant way to present your offer to your visitors. Create a new pricing table now and copy-paste the shortcode anywhere.

10K active installs v5.1.13 PHP + WP 3.6+ Updated Jan 29, 2026
pricespricingpricing-tablepricing-tablesshortcode
95
A · Safe
CVEs total5
Unpatched0
Last CVEJan 6, 2026
Safety Verdict

Is Responsive Pricing Table Safe to Use in 2026?

Generally Safe

Score 95/100

Responsive Pricing Table has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Jan 6, 2026Updated 2mo ago
Risk Assessment

The static analysis of dk-pricr-responsive-pricing-table v5.1.13 reveals a mixed security posture. While the plugin demonstrates good practices in certain areas, like the absence of dangerous functions, file operations, and external HTTP requests, and all SQL queries utilize prepared statements, there are significant concerns. The output escaping is only 52% properly escaped, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might not be adequately neutralized before being displayed. The lack of taint analysis data is also a concern, as it prevents a deeper understanding of how data flows through the plugin and if there are any unsanitized paths, although the absence of critical/high severity flows is a positive sign.

The vulnerability history for this plugin is a major red flag. With a total of 5 known CVEs, all of which are medium severity and focused on basic XSS and input neutralization issues, it suggests a recurring pattern of insecure coding practices related to handling user-provided data. The fact that the last vulnerability was recorded in early 2026, even though the current version is 5.1.13, is highly unusual and may indicate issues with the timestamp data or potentially future vulnerabilities. The consistent history of XSS-related vulnerabilities, even if medium severity, highlights a fundamental weakness in how the plugin sanitizes and outputs data.

In conclusion, while the plugin implements some security best practices, the poor output escaping coupled with a history of numerous XSS vulnerabilities presents a significant risk. The plugin's attack surface is relatively small, and entry points are secured, but the lack of robust output sanitization is a critical flaw that could be exploited. Users should exercise extreme caution and ensure they are using the absolute latest patched version, though the provided data on patch status is confusing.

Key Concerns

  • 52% of outputs properly escaped
  • 5 medium severity CVEs
  • Recurring XSS vulnerability types
Vulnerabilities
5

Responsive Pricing Table Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2024
2024
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-15058medium · 6.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Responsive Pricing Table <= 5.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'table_currency'

Jan 6, 2026 Patched in 5.1.13 (7d)
CVE-2025-13418medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Pricing Table <= 5.1.12 - Authenticated (Author+) Stored Cross-Site Scripting

Jan 6, 2026 Patched in 5.1.13 (7d)
CVE-2024-1333medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Pricing Table <= 5.1.10 - Authenticated (Author+) Stored Cross-Site Scripting

Feb 26, 2024 Patched in 5.1.11 (12d)
CVE-2023-4810medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Pricing Table < 5.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings

Nov 7, 2023 Patched in 5.1.8 (77d)
CVE-2022-46855medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Responsive Pricing Table <= 5.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 7, 2023 Patched in 5.1.7 (350d)
Code Analysis
Analyzed Mar 16, 2026

Responsive Pricing Table Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
43 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

52% escaped83 total outputs
Attack Surface

Responsive Pricing Table Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[rpt] inc\rpt-shortcode.php:4
WordPress Hooks 14
actionadmin_enqueue_scriptsinc\rpt-admin-scripts.php:4
actionwp_enqueue_scriptsinc\rpt-front-scripts.php:4
actionadmin_initinc\rpt-metaboxes-help.php:4
actionadmin_initinc\rpt-metaboxes-plans.php:18
actionadmin_initinc\rpt-metaboxes-pro.php:4
actionadmin_initinc\rpt-metaboxes-settings.php:108
actioninitinc\rpt-post-type.php:4
filterpost_updated_messagesinc\rpt-post-type.php:46
actionadmin_initinc\rpt-pro-version-check.php:4
actionadmin_noticesinc\rpt-pro-version-check.php:10
actionsave_postinc\rpt-save-metaboxes.php:4
actionmanage_rpt_pricing_table_posts_custom_columninc\rpt-shortcode-column.php:4
filtermanage_rpt_pricing_table_posts_columnsinc\rpt-shortcode-column.php:19
actionplugins_loadedinc\rpt-text-domain.php:4
Maintenance & Trust

Responsive Pricing Table Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version
Downloads500K

Community Trust

Rating92/100
Number of ratings92
Active installs10K
Developer Profile

Responsive Pricing Table Developer Profile

WP Darko

8 plugins · 59K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
175 days
View full developer profile
Detection Fingerprints

How We Detect Responsive Pricing Table

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dk-pricr-responsive-pricing-table/css/rpt_style.min.css/wp-content/plugins/dk-pricr-responsive-pricing-table/dmb/dmb.min.css/wp-content/plugins/dk-pricr-responsive-pricing-table/dmb/dmb.min.js/wp-content/plugins/dk-pricr-responsive-pricing-table/js/rpt.min.js/wp-content/plugins/dk-pricr-responsive-pricing-table/img/rpt_recommended.png
Version Parameters
dk-pricr-responsive-pricing-table/css/rpt_style.min.css?ver=dk-pricr-responsive-pricing-table/dmb/dmb.min.css?ver=dk-pricr-responsive-pricing-table/dmb/dmb.min.js?ver=dk-pricr-responsive-pricing-table/js/rpt.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
rpt_plansrpt_sm_titlerpt_xsm_titlerpt_sm_subtitlerpt_xsm_subtitlerpt_sm_descriptionrpt_sm_pricerpt_xsm_price+6 more
Data Attributes
data-plugin-name="dk-pricr-responsive-pricing-table"data-plugin-version="5.1.13"
JS Globals
objectL10n
Shortcode Output
<div id="rpt_pricr"<div class="rpt_plans<img style="height:30px !important; width:30px !important;" class="rpt_recommended" src="
FAQ

Frequently Asked Questions about Responsive Pricing Table