
Pronamic Client Security & Risk Analysis
wordpress.org/plugins/pronamic-clientWordPress plugin for Pronamic clients.
Is Pronamic Client Safe to Use in 2026?
Generally Safe
Score 100/100Pronamic Client has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pronamic-client" v2.3.0 plugin demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and the plugin's clean vulnerability history are significant positive indicators, suggesting a history of secure development practices or diligent patching of past issues. The static analysis reveals a very small attack surface with no apparent unprotected entry points, which is excellent. Furthermore, all SQL queries are properly prepared, and there are no critical or high-severity taint flows identified, indicating good sanitization of potential malicious inputs.
However, there are areas for improvement. The output escaping is not consistently applied, with 32% of outputs not being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without proper sanitization. While nonce and capability checks are present, their limited scope (only one of each) might not cover all potential privilege escalation or CSRF vectors if the plugin's functionality were to expand or be used in complex scenarios. The presence of a bundled library (PHPMailer) is also noted; while not inherently a vulnerability, it introduces a dependency that could become a security concern if the bundled version is outdated and has known vulnerabilities.
In conclusion, the plugin is in a good state, primarily due to its lack of historical vulnerabilities and small, secured attack surface. The most significant concern is the imperfect output escaping, which requires immediate attention to prevent potential XSS flaws. The plugin's strengths lie in its data handling (prepared SQL, no critical taint flows) and protected entry points. Addressing the output escaping and ensuring bundled libraries are kept up-to-date should be the priority to further enhance its security.
Key Concerns
- Improper output escaping detected
- Bundled PHPMailer library
Pronamic Client Security Vulnerabilities
Pronamic Client Release Timeline
Pronamic Client Code Analysis
Bundled Libraries
Output Escaping
Pronamic Client Attack Surface
WordPress Hooks 9
Maintenance & Trust
Pronamic Client Maintenance & Trust
Maintenance Signals
Community Trust
Pronamic Client Alternatives
Pronamic Pay
pronamic-ideal
The Pronamic Pay plugin adds payment methods like iDEAL, Bancontact, credit card and more to your WordPress site for a variety of payment providers.
Pronamic Google Maps
pronamic-google-maps
This plugin makes it easy to add Google Maps to your WordPress post, pages or other custom post types.
Pronamic Pay with Mollie for Gravity Forms
pronamic-pay-with-mollie-for-gravity-forms
Connect Mollie to Gravity Forms with Pronamic Pay. This free plugin is all that you need to start selling with Gravity Forms.
Pronamic Pay with Mollie for Contact Form 7
pronamic-pay-with-mollie-for-contact-form-7
Connect Mollie to Contact Form 7 with Pronamic Pay. This free plugin is all that you need to start selling with Contact Form 7.
SalesFeed
salesfeed
Add a SalesFeed tracking code to your WordPress site. You need a SalesFeed account.
Pronamic Client Developer Profile
16 plugins · 5K total installs
How We Detect Pronamic Client
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pronamic-client/admin/assets/css/pronamic-client-admin.css/wp-content/plugins/pronamic-client/classes/Adminer/resources/adminer/css/theme.css/wp-content/plugins/pronamic-client/classes/Adminer/resources/adminer/css/design.css/wp-content/plugins/pronamic-client/classes/Adminer/resources/adminer/js/adminer.js/wp-content/plugins/pronamic-client/classes/Adminer/resources/adminer/external/jquery/jquery.js/wp-content/plugins/pronamic-client/admin/assets/js/pronamic-client-admin.js/wp-content/plugins/pronamic-client/admin/includes/field-input-color.php/wp-content/plugins/pronamic-client/admin/includes/field-input-url.phppronamic-client/admin/assets/css/pronamic-client-admin.css?ver=pronamic-client/admin/assets/js/pronamic-client-admin.js?ver=HTML / DOM Fingerprints
pronamic-color-pickerpronamic-media-pickerPronamic Client settings pagedata-frame-titledata-button-textdata-library-typepronamic_client_media/wp-json/pronamic-client/v1/settings