First Data for Paid Memberships Pro Security & Risk Analysis

wordpress.org/plugins/first-data-for-pmpro

First Data for Paid Memberships Pro allows merchants to accept all major credit cards for both one-time and recurring membership payments.

10 active installs v1.0.1 PHP + WP 3.5+ Updated Jan 18, 2018
first-datafirstdatapaid-memberships-propayeezypmpro
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is First Data for Paid Memberships Pro Safe to Use in 2026?

Generally Safe

Score 85/100

First Data for Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'first-data-for-pmpro' plugin version 1.0.1 presents a generally good security posture based on the provided static analysis. It exhibits a clean code signal landscape with no detected dangerous functions, no raw SQL queries, and a high rate of output escaping. Furthermore, the absence of file operations and external HTTP requests, along with zero reported CVEs, suggests a solid track record and careful development. The plugin also has no apparent attack surface with unauthenticated entry points, which is a significant strength.

Key Concerns

  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
  • External HTTP request without clear security context
  • Limited output escaping on some outputs
Vulnerabilities
None known

First Data for Paid Memberships Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

First Data for Paid Memberships Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped6 total outputs
Attack Surface

First Data for Paid Memberships Pro Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitclasses\class.pmprogateway_firstdata.php:6
filterpmpro_gatewaysclasses\class.pmprogateway_firstdata.php:27
filterpmpro_payment_optionsclasses\class.pmprogateway_firstdata.php:30
filterpmpro_payment_option_fieldsclasses\class.pmprogateway_firstdata.php:31
actionplugins_loadedpmpro-firstdata-gateway.php:51
Maintenance & Trust

First Data for Paid Memberships Pro Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 18, 2018
PHP min version
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

First Data for Paid Memberships Pro Developer Profile

cardpaysolutions

4 plugins · 1K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect First Data for Paid Memberships Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/first-data-for-pmpro/classes/class.pmprogateway_firstdata.php/wp-content/plugins/first-data-for-pmpro/classes/class.pmprogateway_firstdata_api.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about First Data for Paid Memberships Pro