
Pelcro: Content Subscription Platform Security & Risk Analysis
wordpress.org/plugins/pay-to-viewThe #1 Content Subscription Platform. All the tools you need to drive subscription revenue from your audience. Setup a membership paywall in minutes.
Is Pelcro: Content Subscription Platform Safe to Use in 2026?
Generally Safe
Score 85/100Pelcro: Content Subscription Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'pay-to-view' plugin v3.0.4 reveals a seemingly good security posture with no identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) lacking authentication or proper permission checks. The code also demonstrates positive practices by using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. However, a significant concern arises from the output escaping. With 50% of outputs not being properly escaped, this presents a potential risk for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is directly reflected in the output without proper sanitization.
The vulnerability history is clean, with no recorded CVEs. This, coupled with the absence of critical or high-severity taint flows, suggests that the plugin has historically been secure or that vulnerabilities have been promptly addressed. Despite the lack of historical issues, the partial output escaping is a notable weakness that could be exploited. Therefore, while the plugin demonstrates good foundational security practices, the unescaped outputs represent a tangible, albeit potentially low-impact, risk that requires attention. Overall, the plugin shows strengths in its controlled attack surface and data handling but has a clear area for improvement regarding output sanitization.
Key Concerns
- Unescaped output
Pelcro: Content Subscription Platform Security Vulnerabilities
Pelcro: Content Subscription Platform Code Analysis
Output Escaping
Pelcro: Content Subscription Platform Attack Surface
WordPress Hooks 4
Maintenance & Trust
Pelcro: Content Subscription Platform Maintenance & Trust
Maintenance Signals
Community Trust
Pelcro: Content Subscription Platform Alternatives
Leaky Paywall
leaky-paywall
The subscription engine for news & niche publishers.
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
paid-member-subscriptions
Feature-packed membership plugin for creating subscription plans, adding recurring payments & content restriction on your membership site.
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
s2member
❤️ Excellent membership plugin! Easy, quick, flexible. Monetize your site with memberships and subscriptions. Protect content instantly and securely.
codoc
codoc
A WordPress plugin for monetizing your website with paid articles, Reader Plans, and tipping.
Pelcro: Content Subscription Platform Developer Profile
1 plugin · 10 total installs
How We Detect Pelcro: Content Subscription Platform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pay-to-view/includes/admin/admin-handler.php/wp-content/plugins/pay-to-view/includes/functions.php/wp-content/plugins/pay-to-view/includes/templates.phpHTML / DOM Fingerprints
afw.siteid