Payment Gateway for QPayPro on Formidable Security & Risk Analysis

wordpress.org/plugins/frm-qpaypro

Wordpress plugin that connects formidable forms with QPayPro payment gateway.

0 active installs v0.0.4 PHP 5.2.4+ WP 4.0+ Updated Mar 2, 2021
ecommerceformidableguatemalapaymentqpaypro
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for QPayPro on Formidable Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for QPayPro on Formidable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The frm-qpaypro plugin v0.0.4 presents a mixed security posture. On the positive side, the code demonstrates good practices by utilizing prepared statements for all SQL queries, avoiding dangerous functions, and properly escaping a high percentage (86%) of output. There are also no recorded vulnerabilities or CVEs for this plugin, suggesting a history of secure development or a lack of widespread targeting. However, a significant concern arises from the attack surface analysis: there is one AJAX handler that lacks any authentication checks. This unprotected entry point is a critical weakness that could be exploited by unauthenticated users, potentially leading to unintended actions or data manipulation within the WordPress environment. The absence of any taint analysis results could indicate a very small code base or that the analysis tooling did not find any relevant flows to report, but it also means there's no explicit confirmation of how user-supplied data is handled in all potential execution paths. In conclusion, while the plugin has strengths in its SQL handling and output escaping, the single unprotected AJAX endpoint introduces a notable risk that overshadows these positive aspects.

Key Concerns

  • Unprotected AJAX handler
  • No capability checks on entry points
  • Taint analysis data not provided/null
Vulnerabilities
None known

Payment Gateway for QPayPro on Formidable Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Payment Gateway for QPayPro on Formidable Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
32 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

86% escaped37 total outputs
Attack Surface
1 unprotected

Payment Gateway for QPayPro on Formidable Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_frm_qpp_check_apikeyadmin\wp-actions.php:38
WordPress Hooks 7
actionfrm_qpp_api_request_completedadmin\controllers\class-frmqppappcontroller.php:132
actionfrm_additional_form_optionsadmin\wp-actions.php:24
actionfrm_add_settings_sectionadmin\wp-actions.php:36
filterfrm_include_credit_cardadmin\wp-filters.php:5
filterfrm_validate_entryadmin\wp-filters.php:34
filterfrm_invalid_error_messageadmin\wp-filters.php:43
filterfrm_form_options_before_updateadmin\wp-filters.php:71
Maintenance & Trust

Payment Gateway for QPayPro on Formidable Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 2, 2021
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Payment Gateway for QPayPro on Formidable Developer Profile

Edwin Xico (XicoOfficial)

6 plugins · 100 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for QPayPro on Formidable

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/frm-qpaypro/js/back_end.js

HTML / DOM Fingerprints

JS Globals
frmQppGlobal
FAQ

Frequently Asked Questions about Payment Gateway for QPayPro on Formidable