Pay Day Loan Application form plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/pay-day-loans-application-form

Pay Day Loan Application gives you an affiliate loan application form from which you will earn 70% commission

10 active installs v1.0 PHP + WP 3.0+ Updated Dec 26, 2012
affiliateloan-applicationpay-daypaydayuk-payday-affiliate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pay Day Loan Application form plugin for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Pay Day Loan Application form plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The plugin "pay-day-loans-application-form" v1.0 exhibits a generally good security posture based on the provided static analysis. The absence of any known CVEs, critical taint flows, dangerous functions, file operations, or external HTTP requests is a strong indicator of careful development. Furthermore, all SQL queries are correctly prepared, and the attack surface appears to be minimal with no unprotected entry points detected.

However, there are significant concerns regarding output escaping. The static analysis indicates that 100% of detected outputs are not properly escaped. This presents a substantial risk for cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the context of a user's browser. The lack of nonce checks and capability checks on the identified shortcode also raises questions about authorization for actions performed by this entry point, though the attack surface is limited to just this one shortcode.

In conclusion, while the plugin demonstrates strengths in areas like secure database interactions and a limited attack surface, the critical weakness in output escaping overshadows these positives. The plugin is vulnerable to XSS attacks, which can have severe security implications. The absence of past vulnerabilities is positive but does not mitigate the current risks identified in the code.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks on entry point
  • Missing capability checks on entry point
Vulnerabilities
None known

Pay Day Loan Application form plugin for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pay Day Loan Application form plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Pay Day Loan Application form plugin for WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[payday] payday.php:12
WordPress Hooks 1
actionadmin_menupayday.php:43
Maintenance & Trust

Pay Day Loan Application form plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedDec 26, 2012
PHP min version
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

Pay Day Loan Application form plugin for WordPress Developer Profile

gary.solomon@gmail.com

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pay Day Loan Application form plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapsubmit
Data Attributes
id="paydayloanaffiliate"name="paydayloanaffiliate"value="<?php echo get_option('paydayloanaffiliate'); ?>"name="action"value="update"name="page_options"+1 more
Shortcode Output
<iframe src="https://m.mobi-money.co.uk/plugin/apply.php?height=&width=&affiliate=" width="
FAQ

Frequently Asked Questions about Pay Day Loan Application form plugin for WordPress