MemberPress payment addon – Novalnet AG Security & Risk Analysis

wordpress.org/plugins/novalnet-payment-addon-memberpress

Novalnet payment addon provides all popular online payment methods for your MemberPress webshop.

0 active installs v1.0.1 PHP + WP 5.0+ Updated Dec 29, 2023
credit-cardsnovalnet-paymentpayment-gatewaypayments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MemberPress payment addon – Novalnet AG Safe to Use in 2026?

Generally Safe

Score 85/100

MemberPress payment addon – Novalnet AG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "novalnet-payment-addon-memberpress" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of direct SQL queries, reliance on prepared statements, and 100% output escaping are excellent indicators of secure coding practices. Furthermore, the lack of any reported vulnerabilities in its history significantly bolsters confidence in its security. The plugin also demonstrates good practice by implementing nonce checks on its entry points.

However, there are a few areas that warrant attention. The absence of capability checks on the AJAX handlers, despite the presence of nonce checks, leaves a potential gap. While nonce checks prevent CSRF attacks, capability checks ensure that only authorized users can perform specific actions. The single external HTTP request, while not inherently insecure, represents an external dependency that could potentially be a vector if the external service is compromised or misconfigured. Taint analysis showing zero flows with unsanitized paths is a positive sign, indicating no immediate risks from user-supplied data manipulation.

In conclusion, this plugin appears to be well-developed with a focus on security fundamentals. The primary area for improvement lies in strengthening authentication and authorization by implementing capability checks for its AJAX handlers. Addressing this would further solidify its already robust security profile.

Key Concerns

  • AJAX handlers without capability checks
Vulnerabilities
None known

MemberPress payment addon – Novalnet AG Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MemberPress payment addon – Novalnet AG Release Timeline

v1.0.0
Code Analysis
Analyzed Mar 17, 2026

MemberPress payment addon – Novalnet AG Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
98 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped98 total outputs
Attack Surface

MemberPress payment addon – Novalnet AG Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_novalnet_get_merchant_detailsclass-meprnovalnet.php:43
authwp_ajax_novalnet_configure_webhookclass-meprnovalnet.php:44
WordPress Hooks 10
filtermepr-gateway-pathsclass-meprnovalnet.php:38
filtermepr-ctrls-pathsclass-meprnovalnet.php:39
filtermepr-email-pathsclass-meprnovalnet.php:40
filtermepr_view_pathsclass-meprnovalnet.php:41
actionmepr-options-admin-enqueue-scriptclass-meprnovalnet.php:42
actionmepr-admin-txn-form-before-userincludes\MeprNovalnetGateway.php:104
filtermepr_transaction_email_varsincludes\MeprNovalnetGateway.php:105
filtermepr_transaction_email_paramsincludes\MeprNovalnetGateway.php:106
actionplugins_loadedmemberpress-novalnet-addon.php:21
actionadmin_noticesmemberpress-novalnet-addon.php:41
Maintenance & Trust

MemberPress payment addon – Novalnet AG Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 29, 2023
PHP min version
Downloads920

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MemberPress payment addon – Novalnet AG Developer Profile

Novalnet

4 plugins · 1K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MemberPress payment addon – Novalnet AG

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/novalnet-payment-addon-memberpress/assets/js/config.js
Script Paths
/wp-content/plugins/novalnet-payment-addon-memberpress/assets/js/config.js
Version Parameters
novalnet-payment-addon-memberpress/assets/js/config.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-mepr-novalnet-signaturedata-mepr-novalnet-access-key
JS Globals
MeprNovalnet
REST Endpoints
/wp-json/wp/v2/users/wp-json/novalnet-payment-addon-memberpress/v1/webhook
FAQ

Frequently Asked Questions about MemberPress payment addon – Novalnet AG