
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Security & Risk Analysis
wordpress.org/plugins/paid-membershipMonetize digital content with creator subscriptions, micro-payments, and a tokens wallet system.
Is MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Safe to Use in 2026?
Generally Safe
Score 96/100MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet has a strong security track record. Known vulnerabilities have been patched promptly.
The "paid-membership" plugin v3.2.5 presents a mixed security posture. On the positive side, it demonstrates good practices with a high percentage of SQL queries using prepared statements and properly escaped outputs. The plugin also shows a good number of nonce and capability checks. However, the significant presence of 8 unprotected AJAX handlers creates a substantial attack surface, posing a considerable risk for unauthorized actions or privilege escalation if not properly secured by the calling context.
The taint analysis reveals 3 high-severity flows with unsanitized paths, indicating potential vulnerabilities where untrusted input could lead to unintended consequences, although no critical severity flows were detected. The vulnerability history shows 5 previously disclosed medium-severity vulnerabilities, primarily related to Cross-site Scripting (XSS) and Cross-Site Request Forgery (CSRF). While there are currently no unpatched CVEs, the history of these common vulnerability types suggests a pattern of potential weaknesses in input sanitization and user action verification.
In conclusion, while the plugin incorporates several strong security measures, the unprotected AJAX endpoints and the history of XSS/CSRF vulnerabilities are significant concerns. The high-severity taint flows warrant immediate investigation. The plugin's strengths lie in its use of prepared statements and output escaping, but the large attack surface without authentication and past vulnerability patterns suggest a need for diligent ongoing security practices and potential code review for the identified taint flows.
Key Concerns
- 8 unprotected AJAX handlers
- 3 high severity taint flows
- 5 known medium severity CVEs
- Use of unserialize()
- Use of preg_replace(/e)
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet <= 3.2.0 - Cross-Site Request Forgery to Settings Reset
MicroPayments <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
MicroPayments <= 3.2.4 - Reflected Cross-Site Scripting
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership <= 1.9.5 - Cross-Site Request Forgery
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Attack Surface
AJAX Handlers 9
Shortcodes 24
WordPress Hooks 33
Scheduled Events 3
Maintenance & Trust
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Maintenance & Trust
Maintenance Signals
Community Trust
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Alternatives
AtomX Services
atomx-services
Generation of purchase codes/tokens for AtomX extension (or based on AtomX) for products and subscriptions.
DL Gift Wallet
dl-gift-wallet
Let customers buy gift credit that’s added directly to the recipient’s account as store credit, usable on both one-off orders and subscriptions.
PREMIUUM Content Monetization
premiuum-content-monetization
Revenue-per-Link™ content monetization. PREMIUUM makes it easy to sell articles, music, videos, files & links via subscriptions and/or micropayments.
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple to use, all-in-one platform, that anyone can set up in just a few minutes!
Wallet for WooCommerce
woo-wallet
A extendable WooCommerce wallet system which support payment, partial payment, cashback reward program as well as refund for your WooCommerce store.
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet Developer Profile
12 plugins · 1K total installs
How We Detect MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/paid-membership/inc/videowhisper-paid-content.css/wp-content/plugins/paid-membership/inc/videowhisper-paid-content.js/wp-content/plugins/paid-membership/inc/videowhisper-paid-content.jspaid-membership/inc/videowhisper-paid-content.css?ver=paid-membership/inc/videowhisper-paid-content.js?ver=HTML / DOM Fingerprints
videowhisper-paid-content-admin<!-- VW PAID CONTENT AREA -->data-videowhisper-paid-contentwindow.vw_paid_contentvar vw_paid_content[videowhisper_creator_stats[videowhisper_content_list[videowhisper_my_content[videowhisper_my_purchases