Pricing Table by Supsystic Security & Risk Analysis

wordpress.org/plugins/pricing-table-by-supsystic

Pricing Table generator by Supsystic allows you to create responsive pricing tables or comparison table without any programming skills

10K active installs v1.10.02 PHP + WP + Updated Nov 26, 2025
chartcomparison-tableprice-chartprice-planpricing-table
95
A · Safe
CVEs total6
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is Pricing Table by Supsystic Safe to Use in 2026?

Generally Safe

Score 95/100

Pricing Table by Supsystic has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Apr 22, 2024Updated 4mo ago
Risk Assessment

The plugin "pricing-table-by-supsystic" v1.10.02 presents a mixed security posture. While the static analysis reveals a limited attack surface with no identified unprotected entry points and a decent percentage of SQL queries using prepared statements, several concerning signals are present. The use of the `unserialize` function three times is a significant risk, as it can lead to deserialization vulnerabilities if not handled with extreme care and validation. Additionally, the low percentage of properly escaped output (33%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history is also a major red flag, with six known CVEs, including four high-severity ones, and a recent vulnerability reported in April 2024. The common vulnerability types like Injection, XSS, SQL Injection, CSRF, and Missing Authorization indicate recurring security weaknesses within the plugin's development over time. The lack of currently unpatched CVEs is a positive, but the pattern of past vulnerabilities and the identified code signals like unserialize and poor output escaping create a notable risk.

Key Concerns

  • Dangerous function `unserialize` used
  • Low percentage of properly escaped output
  • Multiple High severity CVEs in history
  • Recent vulnerability (April 2024)
  • Bundled outdated library: TinyMCE v1.0
Vulnerabilities
6

Pricing Table by Supsystic Security Vulnerabilities

CVEs by Year

3 CVEs in 2020
2020
1 CVE in 2021
2021
1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
4
Medium
1
Low
1

6 total CVEs

CVE-2024-32790low · 2.7Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Pricing Table by Supsystic <= 1.9.12 - Authenticated (Admin+) Content Injection

Apr 22, 2024 Patched in 1.9.13 (8d)
CVE-2021-46782medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pricing Table by Supsystic <= 1.9.4 - Reflected Cross-Site Scripting

Apr 9, 2022 Patched in 1.9.5 (654d)
WF-9a9c8c4f-ce07-4fe5-a573-ece675d51441-pricing-table-by-supsystichigh · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Pricing Table by Supsystic <= 1.8.8 - Boolean-Based Blind SQL Injections

Feb 8, 2021 Patched in 1.8.9 (1079d)
CVE-2020-9394high · 8.8Cross-Site Request Forgery (CSRF)

Pricing Table by Supsystic <= 1.8.1 - Cross-Site Request Forgery to Cross-Site Scripting and Setting Changes

Feb 25, 2020 Patched in 1.8.2 (1428d)
CVE-2020-9393high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pricing Table by Supsystic <= 1.8.1 - Unauthenticated Stored Cross-Site Scripting

Feb 25, 2020 Patched in 1.8.2 (1428d)
CVE-2020-9392high · 7.3Missing Authorization

Pricing Table by Supsystic <= 1.8.1 - Missing Authorization on AJAX Actions

Feb 25, 2020 Patched in 1.8.2 (1428d)
Code Analysis
Analyzed Mar 16, 2026

Pricing Table by Supsystic Code Analysis

Dangerous Functions
3
Raw SQL Queries
22
19 prepared
Unescaped Output
203
99 escaped
Nonce Checks
3
Capability Checks
2
File Operations
20
External Requests
4
Bundled Libraries
2

Dangerous Functions Found

unserializelist($this->template, $this->name, $this->type, $this->starts, $this->ends, $this->profiles) = unserclasses\Twig\Profiler\Profile.php:158
unserializereturn $safe ? @unserialize($data) : unserialize($data);classes\utils.php:13
unserializereturn $safe ? @unserialize($data) : unserialize($data);classes\utils.php:13

Bundled Libraries

TinyMCE1.0jQuery

SQL Query Safety

46% prepared41 total queries

Output Escaping

33% escaped302 total outputs
Attack Surface

Pricing Table by Supsystic Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpseo_filter_shortcodesmodules\tables\mod.php:22
WordPress Hooks 17
actionadmin_noticesclasses\errors.php:36
filterthe_contentclasses\errors.php:42
actioninitclasses\frame.php:87
actioninitclasses\frame.php:97
actioninitclasses\frame.php:101
actioninitclasses\frame.php:117
actioninitclasses\frame.php:213
filtersafe_style_cssclasses\req.php:113
actionactivated_pluginclasses\utils.php:226
filtersafe_style_cssfunctions.php:365
actionadmin_menumodules\adminmenu\mod.php:7
filterwp_mail_content_typemodules\mail\mod.php:18
actionadmin_footermodules\supsystic_promo\mod.php:21
actionadmin_noticesmodules\supsystic_promo\mod.php:49
filterwp_footermodules\tables\mod.php:10
actionadmin_bar_menumodules\tables\mod.php:18
actionadmin_enqueue_scriptsmodules\templates\mod.php:17
Maintenance & Trust

Pricing Table by Supsystic Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 26, 2025
PHP min version
Downloads1.2M

Community Trust

Rating82/100
Number of ratings288
Active installs10K
Developer Profile

Pricing Table by Supsystic Developer Profile

supsystic

7 plugins · 97K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
610 days
View full developer profile
Detection Fingerprints

How We Detect Pricing Table by Supsystic

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pricing-table-by-supsystic/assets/css/style.css/wp-content/plugins/pricing-table-by-supsystic/assets/js/scripts.js
Script Paths
/wp-content/plugins/pricing-table-by-supsystic/assets/js/scripts.js
Version Parameters
pricing-table-by-supsystic/assets/css/style.css?ver=pricing-table-by-supsystic/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ptsProTabsContentptsProTabsNavptsSaleLabelptsTableContentptsTableFeaturesptsTableTitle
Data Attributes
data-pts-iddata-pts-type
JS Globals
ptsGlobal
Shortcode Output
[supsystic-pricing-table
FAQ

Frequently Asked Questions about Pricing Table by Supsystic