Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Security & Risk Analysis

wordpress.org/plugins/lemon-squeezy

Sell digital products, subscriptions, memberships, and software licenses on your WordPress website.

400 active installs v1.4.3 PHP 7.0+ WP 5.3+ Updated Dec 2, 2025
checkoutdigital-productsecommercepaymentssubscriptions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Safe to Use in 2026?

Generally Safe

Score 100/100

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "lemon-squeezy" plugin v1.4.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, critical or high severity vulnerabilities, and a clean vulnerability history suggests a generally well-maintained and secure plugin. The static analysis further supports this, showing a complete lack of dangerous functions, raw SQL queries, and unsanitized taint flows. All SQL queries are prepared, output is consistently escaped, and there are no file operations or known bundled libraries that could introduce vulnerabilities.

However, the analysis does reveal some areas for attention. While the attack surface is reported as zero entry points, which is excellent, the plugin makes ten external HTTP requests. Without further information on these requests and their validation, they represent a potential, albeit not explicitly defined in this data, vector for issues like SSRF or data leakage. The presence of only one nonce check and two capability checks, while indicating some security measures, is relatively low. In larger or more complex plugins, these numbers might be concerning, but given the overall clean state, it suggests the plugin's functionality might be straightforward, requiring fewer checks.

In conclusion, "lemon-squeezy" v1.4.3 appears to be a very secure plugin, demonstrating excellent practices in key areas like SQL sanitization, output escaping, and avoiding known vulnerability types. The lack of any recorded security incidents is a significant positive. The minor areas for potential improvement lie in the oversight of external HTTP requests and potentially increasing the rigor of nonce and capability checks if the plugin's functionality were to expand in complexity. For its current state, the risk is low.

Key Concerns

  • Potential risk from uninspected external HTTP requests
  • Limited number of nonce and capability checks
Vulnerabilities
None known

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Release Timeline

v1.4.3Current
v1.4.2
v1.4.1
v1.4.0
v1.3.0
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
10
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedlemonsqueezy.php:38
filterhttps_ssl_verifylemonsqueezy.php:41
actionadmin_menusrc\class-lsq-admin.php:33
actionadmin_enqueue_scriptssrc\class-lsq-admin.php:34
actioninitsrc\class-lsq-admin.php:35
filteroption_lsq_api_keysrc\class-lsq-admin.php:36
filterallowed_redirect_hostssrc\class-lsq-admin.php:37
actioninitsrc\class-lsq-register-block.php:34
filterrender_blocksrc\class-lsq-register-block.php:35
filterblock_categories_allsrc\class-lsq-register-block.php:36
actionrest_api_initsrc\class-lsq-rest-controller.php:34
Maintenance & Trust

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 2, 2025
PHP min version7.0
Downloads9K

Community Trust

Rating74/100
Number of ratings3
Active installs400
Developer Profile

Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses Developer Profile

Lemon Squeezy

1 plugin · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lemon-squeezy/build/admin.js/wp-content/plugins/lemon-squeezy/build/admin.css/wp-content/plugins/lemon-squeezy/build/editor.js/wp-content/plugins/lemon-squeezy/build/script.js/wp-content/plugins/lemon-squeezy/build/style-script.css/wp-content/plugins/lemon-squeezy/images/ls-logo.svg/wp-content/plugins/lemon-squeezy/images/ls-icon.svg
Script Paths
/wp-content/plugins/lemon-squeezy/build/admin.js/wp-content/plugins/lemon-squeezy/build/editor.js/wp-content/plugins/lemon-squeezy/build/script.js
Version Parameters
lemon-squeezy/build/admin.js?ver=lemon-squeezy/build/admin.css?ver=lemon-squeezy/build/editor.js?ver=lemon-squeezy/build/script.js?ver=lemon-squeezy/build/style-script.css?ver=

HTML / DOM Fingerprints

CSS Classes
lsq-logo
Data Attributes
data-lsq-product-id
JS Globals
LemonsqueezylsData
REST Endpoints
/wp-json/lemonsqueezy/v1/products
Shortcode Output
[lemonsqueezy_buy_button]
FAQ

Frequently Asked Questions about Lemon Squeezy — Sell Digital Products, Subscriptions, and Licenses