ProAbono – Subscription billing Security & Risk Analysis

wordpress.org/plugins/proabono

ProAbono is made by WordPress experts to go further with WP sites, and help you grow your business by easily selling your services by paying subscript …

0 active installs v2.0.16 PHP 7.4.0+ WP 5.0.0+ Updated Unknown
content-protectionproabonorecurring-billingsubscriptionsubscription-billing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ProAbono – Subscription billing Safe to Use in 2026?

Generally Safe

Score 100/100

ProAbono – Subscription billing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "proabono" plugin v2.0.16 exhibits a generally good security posture based on the static analysis. The absence of known CVEs and a clean vulnerability history is a significant strength, suggesting a well-maintained and security-conscious development approach. The plugin also demonstrates good practices in its code signals, with all SQL queries utilizing prepared statements and a high percentage of output escaping. The limited attack surface and the absence of critical or high-severity taint flows further contribute to its positive security assessment.

However, there are a few areas that warrant attention. The lack of nonce checks on any entry points, while not explicitly identified as a direct vulnerability in the taint analysis, could be a potential weakness. Additionally, the presence of external HTTP requests without explicit mention of verification or sanitization could introduce risks if the target endpoints are compromised or misconfigured. While the plugin's history is clean, the absence of any recorded vulnerabilities could also simply mean it hasn't been subjected to rigorous external audits or encountered exploitable scenarios yet.

In conclusion, "proabono" v2.0.16 appears to be a relatively secure plugin, with strengths in its SQL handling, output escaping, and lack of known vulnerabilities. The main areas for improvement lie in implementing nonce checks for enhanced security against CSRF attacks and ensuring the secure handling of external HTTP requests. The plugin's clean record is encouraging, but continuous vigilance and adherence to best security practices remain crucial.

Key Concerns

  • No nonce checks found
  • External HTTP requests present
Vulnerabilities
None known

ProAbono – Subscription billing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ProAbono – Subscription billing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
45 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

92% escaped49 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
PA_widget_script (functions.proabono-widget.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ProAbono – Subscription billing Attack Surface

Entry Points5
Unprotected0

Shortcodes 5

[ProAbono-customerportal] proabono.php:104
[ProAbono-content-restriction] proabono.php:105
[ProAbono-ping] proabono.php:106
[ProAbono-offers] proabono.php:107
[ProAbono-open-widget] proabono.php:108
WordPress Hooks 12
actionadmin_initclass.proabono-settings.php:12
actionadmin_menuclass.proabono-settings.php:13
actionwp_headproabono.php:98
filterwalker_nav_menu_start_elproabono.php:115
actioninitproabono.php:119
actionuser_registerproabono.php:130
actionadded_optionproabono.php:132
actionupdated_optionproabono.php:133
filterlogin_redirectproabono.php:139
actionuser_registerproabono.php:146
filterregistration_redirectproabono.php:152
filtershow_admin_barproabono.php:157
Maintenance & Trust

ProAbono – Subscription billing Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ProAbono – Subscription billing Developer Profile

ProAbono

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ProAbono – Subscription billing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/proabono/assets/css/proabono.css/wp-content/plugins/proabono/assets/js/proabono.js/wp-content/plugins/proabono/assets/css/bootstrap.min.css/wp-content/plugins/proabono/assets/css/font-awesome.min.css/wp-content/plugins/proabono/assets/js/bootstrap.min.js/wp-content/plugins/proabono/assets/js/proabono_admin.js/wp-content/plugins/proabono/assets/js/proabono_widget.js
Version Parameters
proabono/assets/css/proabono.css?ver=proabono/assets/js/proabono.js?ver=proabono/assets/css/bootstrap.min.css?ver=proabono/assets/css/font-awesome.min.css?ver=proabono/assets/js/bootstrap.min.js?ver=proabono/assets/js/proabono_admin.js?ver=proabono/assets/js/proabono_widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
proabono-customer-portalproabono-customer-widgetproabono-customer-menu
HTML Comments
<!-- ProAbono-open-widget --><!-- ProAbono-customerportal --><!-- ProAbono-content-restriction --><!-- ProAbono-ping -->+1 more
Data Attributes
data-proabono-widget-keydata-proabono-widget-element
JS Globals
window.proabono_init_widget
Shortcode Output
[ProAbono-customerportal][ProAbono-content-restriction][ProAbono-ping][ProAbono-offers]
FAQ

Frequently Asked Questions about ProAbono – Subscription billing