
Paypal Subscriptions Security & Risk Analysis
wordpress.org/plugins/gpls-paypal-subscriptionsPaypal Subscriptions plugin integrates PayPal subscriptions with WordPress easily.
Is Paypal Subscriptions Safe to Use in 2026?
Generally Safe
Score 85/100Paypal Subscriptions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gpls-paypal-subscriptions plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, which is a positive indicator. The high percentage of SQL queries using prepared statements and properly escaped outputs are also commendable security practices. Furthermore, the plugin incorporates nonce and capability checks, further reinforcing its defenses.
However, a specific concern arises from the taint analysis, which identified two flows with unsanitized paths. While no critical or high-severity vulnerabilities were flagged, unsanitized paths can be a precursor to path traversal or file inclusion vulnerabilities, especially if the paths are derived from user input. The presence of file operations, even if not directly linked to a critical taint flow, warrants careful review in conjunction with these unsanitized paths. The plugin's vulnerability history shows no known CVEs, which is a positive sign, suggesting a relatively stable and secure codebase in the past.
In conclusion, the plugin demonstrates good security awareness through its adherence to best practices in input sanitization, output escaping, and access control. The minimal attack surface and lack of past vulnerabilities are strengths. The primary area for improvement and careful scrutiny lies in investigating and remediating the two identified flows with unsanitized paths to proactively prevent potential security weaknesses.
Key Concerns
- Flows with unsanitized paths found
Paypal Subscriptions Security Vulnerabilities
Paypal Subscriptions Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Paypal Subscriptions Attack Surface
WordPress Hooks 18
Maintenance & Trust
Paypal Subscriptions Maintenance & Trust
Maintenance Signals
Community Trust
Paypal Subscriptions Alternatives
Chargely Free Subscriptions For Woocommernce
chargely-free-subscriptions-for-woocommerce
Start your Subscription Business in minutes with Chargely. Chargely provides PCI Certified Payment page for your card processing. So that you don't need a PCI Certification.
ReordeRe Lite – Subscriptions For WooCommerce
reordere-lite-subcriptions-for-woocommerce
WooCommerce Subscriptions made simple! ReordeRe Lite enables product subscriptions & recurring payments via PayPal & Stripe. Easy setup!
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Pay with Vipps and MobilePay for WooCommerce
woo-vipps
Official Vipps MobilePay payment plugin for WooCommerce.
Mollie Forms
mollie-forms
Create registration forms with payment methods of Mollie. One-time and recurring payments are possible.
Paypal Subscriptions Developer Profile
20 plugins · 9K total installs
How We Detect Paypal Subscriptions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gpls-paypal-subscriptions/assets/css/style.css/wp-content/plugins/gpls-paypal-subscriptions/assets/js/main.js/wp-content/plugins/gpls-paypal-subscriptions/assets/js/main.jsgpls-paypal-subscriptions/assets/css/style.css?ver=gpls-paypal-subscriptions/assets/js/main.js?ver=HTML / DOM Fingerprints
gpls-paypal-subscriptions-wrapgpls-paypal-subscriptions-buttongpls-pyplss-admin-styles<!-- GPLS PayPal Subscriptions Plugin Starts --><!-- GPLS PayPal Subscriptions Plugin Ends --><!-- GPLS CORE -->data-gpls-paypal-subscriptions-iddata-gpls-paypal-subscriptions-typegpls_paypal_subscriptions_localize_data/wp-json/gpls-paypal-subscriptions/v1/process-payment/wp-json/gpls-paypal-subscriptions/v1/webhook[gpls_paypal_subscribe][gpls_paypal_buy_now]