Dropp Payment Gateway For Restrict Content Pro Security & Risk Analysis

wordpress.org/plugins/dropp-payment-gateway-for-restrict-content-pro

Dropp payment gateway integration for Restrict Content Pro.

0 active installs v1.0.0 PHP 7.2+ WP 5.8+ Updated Apr 22, 2025
content-restrictiondroppmembershippayment-gatewayrestrict-content-pro
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Dropp Payment Gateway For Restrict Content Pro Safe to Use in 2026?

Generally Safe

Score 100/100

Dropp Payment Gateway For Restrict Content Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "dropp-payment-gateway-for-restrict-content-pro" plugin v1.0.0 exhibits a generally strong security posture, with many good practices in place. Notably, 100% of its output is properly escaped, and there are no detected file operations or bundled libraries. The absence of known CVEs and a clean vulnerability history further contribute to this positive assessment. The static analysis indicates a relatively small attack surface, with no unprotected entry points found.

However, there are areas for concern. The plugin utilizes 8 unsanitized paths in its taint analysis, indicating potential risks if these flows are triggered with malicious input, even though no critical or high severity issues were identified. While the plugin uses prepared statements for half of its SQL queries, the remaining half are likely executed as raw SQL, which could be a vulnerability if user input is not properly handled. Additionally, the plugin has 0 capability checks, meaning that access to its functionalities might not be properly restricted based on user roles, which is a significant security oversight for a payment gateway plugin.

In conclusion, the plugin has demonstrated good security hygiene in output sanitization and a lack of historical vulnerabilities. However, the presence of unsanitized taint flows and the complete absence of capability checks represent critical security weaknesses that need immediate attention. Addressing these vulnerabilities will be crucial for ensuring the plugin's secure operation.

Key Concerns

  • 8 unsanitized taint flows
  • 0 capability checks
  • 50% of SQL queries not prepared
Vulnerabilities
None known

Dropp Payment Gateway For Restrict Content Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dropp Payment Gateway For Restrict Content Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
8 prepared
Unescaped Output
0
211 escaped
Nonce Checks
10
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

50% prepared16 total queries

Output Escaping

100% escaped211 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
process_request (dropp-sdk\classes\class-base-payment.php:149)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Dropp Payment Gateway For Restrict Content Pro Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[dropp_payment_rcp] includes\admin-page\class-register-gateway.php:38
[dropp_payment_rcp] includes\class-process-payment.php:38
WordPress Hooks 22
actionplugins_loadeddropp-payment-gateway-for-restrict-content-pro.php:36
actionadmin_noticesdropp-payment-gateway-for-restrict-content-pro.php:41
actionplugins_loadedincludes\admin-page\class-log.php:36
actionadmin_noticesincludes\admin-page\class-log.php:41
actionadmin_menuincludes\admin-page\class-payment-auto-renew.php:30
actionadmin_initincludes\admin-page\class-payment-auto-renew.php:31
actioninitincludes\admin-page\class-payment-auto-renew.php:32
actiondropp_payment_rcp_data_log_cronincludes\admin-page\class-payment-auto-renew.php:33
actionwp_enqueue_scriptsincludes\admin-page\class-register-gateway.php:39
actionadmin_menuincludes\class-log.php:30
actionadmin_initincludes\class-log.php:31
actioninitincludes\class-log.php:32
actiondropp_payment_rcp_data_log_cronincludes\class-log.php:33
actioninitincludes\class-payment-auto-renew.php:31
actiondropp_payment_rcp_dailyincludes\class-payment-auto-renew.php:32
actiondropp_payment_rcp_renew_membershipsincludes\class-payment-auto-renew.php:33
actionwp_enqueue_scriptsincludes\class-process-payment.php:39
filterrcp_payment_gatewaysincludes\class-register-gateway.php:29
actionrcp_payments_settingsincludes\class-register-gateway.php:30
filterrcp_membership_can_cancelincludes\class-register-gateway.php:31
actionrcp_edit_payment_afterincludes\class-register-gateway.php:32
filterrcp_membership_payment_profile_cancelledincludes\class-register-gateway.php:33

Scheduled Events 4

dropp_payment_rcp_data_log_cron
dropp_payment_rcp_data_log_cron
dropp_payment_rcp_daily
dropp_payment_rcp_renew_memberships
Maintenance & Trust

Dropp Payment Gateway For Restrict Content Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 22, 2025
PHP min version7.2
Downloads388

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Dropp Payment Gateway For Restrict Content Pro Developer Profile

Dropp Payment App

4 plugins · 20 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dropp Payment Gateway For Restrict Content Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dropp-payment-gateway-for-restrict-content-pro/assets/js/dropp-rcp-script.js
Script Paths
/wp-content/plugins/dropp-payment-gateway-for-restrict-content-pro/assets/js/dropp-rcp-script.js
Version Parameters
dropp-payment-gateway-for-restrict-content-pro/assets/js/dropp-rcp-script.js?ver=dropp-payment-gateway-for-restrict-content-pro/assets/css/dropp-rcp-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
dropp-payment-rcp-gateway-section
Data Attributes
data-dropp-rcp-api-key
JS Globals
dropp_rcp_payment_gateway_params
Shortcode Output
[dropp_payment_rcp]
FAQ

Frequently Asked Questions about Dropp Payment Gateway For Restrict Content Pro