PayPal API Subscriptions Security & Risk Analysis

wordpress.org/plugins/paypal-api-subscriptions

DEPRECATED — This plugin uses the discontinued PayPal NVP API and handles raw credit card data. Please switch to a modern alternative.

10 active installs v1.2.0 PHP 7.4+ WP 4.0+ Updated Feb 23, 2026
billingdeprecatedpaypalrecurringsubscription
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayPal API Subscriptions Safe to Use in 2026?

Generally Safe

Score 100/100

PayPal API Subscriptions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "paypal-api-subscriptions" plugin v1.2.0 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication or permission checks. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and ensuring all outputs are properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and the presence of at least one capability check further contribute to a secure design. The vulnerability history is clean, with no recorded CVEs, indicating a lack of previously exploited weaknesses.

Vulnerabilities
None known

PayPal API Subscriptions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PayPal API Subscriptions Release Timeline

v1.2.0Current
v1.1.0
v1.0
Code Analysis
Analyzed Apr 16, 2026

PayPal API Subscriptions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

PayPal API Subscriptions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_noticessubscriptions.php:20
filterthe_contentsubscriptions.php:47
Maintenance & Trust

PayPal API Subscriptions Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

PayPal API Subscriptions Developer Profile

zackdesign

5 plugins · 190 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayPal API Subscriptions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<p><em>This subscription form has been retired. Please contact the site administrator.</em></p>
FAQ

Frequently Asked Questions about PayPal API Subscriptions