
MemberPress Square — Accept Square Payments in MemberPress Security & Risk Analysis
wordpress.org/plugins/pay-with-square-in-memberpressWant to integrate Square payments in Memberpress for your wordpress site? Install Memberpress Square to accept Square Payments & create subscriptions.
Is MemberPress Square — Accept Square Payments in MemberPress Safe to Use in 2026?
Generally Safe
Score 100/100MemberPress Square — Accept Square Payments in MemberPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pay-with-square-in-memberpress" plugin v1.3 exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events directly exposed to attack with or without authentication significantly limits the plugin's attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding dangerous functions and file operations. The lack of any recorded vulnerabilities in its history is also a positive indicator of its stability and security.
However, there are notable areas for concern. The output escaping is only properly implemented in 59% of cases, meaning a significant portion of plugin outputs are not adequately sanitized, potentially exposing the site to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly handled before being displayed. The taint analysis revealing 3 flows with unsanitized paths, even though not classified as critical or high severity, warrants attention. While the static analysis shows no direct exploitable vulnerabilities in these flows, it indicates potential weaknesses in how data is handled. The complete lack of nonce and capability checks on any identified entry points, although the attack surface is reported as zero, is a methodological gap. If any entry points were to be introduced or discovered later, their absence of these fundamental WordPress security mechanisms would be a critical oversight.
In conclusion, the plugin is built on a secure foundation with a minimal attack surface and good SQL practices. The primary weakness lies in the insufficient output escaping and the presence of unsanitized data flows. The historical lack of vulnerabilities is encouraging, but the current analysis suggests that careful review and remediation of output escaping and taint flows are necessary to maintain a robust security posture.
Key Concerns
- Unescaped output in 59% of cases
- Taint analysis shows unsanitized paths (3 flows)
- No nonce checks detected
- No capability checks detected
MemberPress Square — Accept Square Payments in MemberPress Security Vulnerabilities
MemberPress Square — Accept Square Payments in MemberPress Release Timeline
MemberPress Square — Accept Square Payments in MemberPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MemberPress Square — Accept Square Payments in MemberPress Attack Surface
WordPress Hooks 15
Maintenance & Trust
MemberPress Square — Accept Square Payments in MemberPress Maintenance & Trust
Maintenance Signals
Community Trust
MemberPress Square — Accept Square Payments in MemberPress Alternatives
Pay with Vipps and MobilePay for WooCommerce
woo-vipps
Official Vipps MobilePay payment plugin for WooCommerce.
Memberful – Membership Plugin
memberful-wp
Sell memberships and restrict access to content with WordPress and Memberful.
Recurio – Ultimate Subscription for WooCommerce
recurio
A powerful and comprehensive WooCommerce subscription management plugin with advanced analytics, automated billing, and customer portal.
Paystack MemberPress
paystack-memberpress
A Memberpress Payment Gateway integration with Paystack for membership subscriptions.
Vipps/MobilePay recurring payments for WooCommerce
vipps-recurring-payments-gateway-for-woocommerce
Vipps/MobilePay recurring payments is perfect if you run a shop with subscription based services or products that would benefit from subscriptions.
MemberPress Square — Accept Square Payments in MemberPress Developer Profile
89 plugins · 1.4M total installs
How We Detect MemberPress Square — Accept Square Payments in MemberPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pay-with-square-in-memberpress/assets/js/admin_script.js/wp-content/plugins/pay-with-square-in-memberpress/assets/js/admin_script.jspay-with-square-in-memberpress/assets/js/admin_script.js?ver=HTML / DOM Fingerprints
disapeared_msgdata-dismissible="notice-one-forever-woosquare"MEPR_FREE_SQUARE_PATHMEPR_FREE_SQUARE_URLMEPR_FREE_SQUARE_IMAGES_URLMEPR_FREE_SQUARE_SANDBOXMEPR_FREE_SQUARE_LIVEMEPR_FREE_SQUARE_PLUGIN_NAME+3 more