
IDPay For Paid Memberships Pro Security & Risk Analysis
wordpress.org/plugins/idpay-paid-memberships-proAfter installing and enabling this plugin, your customers can pay through IDPay gateway.
Is IDPay For Paid Memberships Pro Safe to Use in 2026?
Generally Safe
Score 85/100IDPay For Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The idpay-paid-memberships-pro plugin version 1.2.1 exhibits a concerning security posture due to significant vulnerabilities in its access control mechanisms. While the plugin shows no past CVEs, suggesting a history of relative security, the static analysis reveals critical weaknesses. The presence of two unprotected AJAX handlers represents a direct pathway for unauthorized actions, as there are no nonce or capability checks in place for these entry points. Furthermore, all four SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities, especially when handling user-supplied data. The taint analysis indicating flows with unsanitized paths, though not classified as critical or high, combined with the lack of proper SQL sanitization, points to a substantial risk of data manipulation and potential compromise.
Despite the absence of known vulnerabilities and a high percentage of properly escaped output, the unprotected entry points and raw SQL queries are major concerns. The plugin's attack surface, though small in terms of entry points, is highly exposed. The lack of any nonce or capability checks on the AJAX handlers is a critical oversight that could allow unauthenticated users to trigger potentially sensitive actions within the plugin. The reliance on raw SQL queries without prepared statements is a widespread vulnerability pattern that exposes the database to significant risks. In conclusion, while the plugin has a clean vulnerability history, the current version has several critical security flaws that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL queries without prepared statements
- No nonce checks
- No capability checks
- Taint flows with unsanitized paths
IDPay For Paid Memberships Pro Security Vulnerabilities
IDPay For Paid Memberships Pro Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IDPay For Paid Memberships Pro Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
IDPay For Paid Memberships Pro Maintenance & Trust
Maintenance Signals
Community Trust
IDPay For Paid Memberships Pro Alternatives
IDPay For Restrict Content Pro (RCP)
idpay-for-restrict-content-pro
After installing and enabling this plugin, your customers can pay through IDPay gateway.
Click & Pledge – Paid Memberships Pro
click-pledge-paid-memberships-pro
Click & Pledge payment gateway integration for Paid Memberships Pro with Salesforce support.
IDPay Payment Gateway for Woocommerce
woo-idpay-gateway
IDPay payment method for Woocommerce.
My Members Only – Membership for WordPress
iceyi-members-only
Protect content in posts and pages with shortcodes.
IDPay For Wp Gravity Forms
idpay-gateway-gravity-forms
After installing and enabling this plugin, your customers can pay through IDPay gateway.
IDPay For Paid Memberships Pro Developer Profile
7 plugins · 1K total installs
How We Detect IDPay For Paid Memberships Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/idpay-paid-memberships-pro/idpay-paid-memberships-pro.phpHTML / DOM Fingerprints
gateway_idpaygateway_idpay