
Pronamic Subscriptions Security & Risk Analysis
wordpress.org/plugins/pronamic-subscriptionsThis plugin add some basic subscription functionalities to WordPress.
Is Pronamic Subscriptions Safe to Use in 2026?
Generally Safe
Score 85/100Pronamic Subscriptions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, coupled with a complete lack of direct SQL queries and a commendable effort in output escaping, suggests diligent security practices during development. The presence of nonce and capability checks further bolsters its defensibility against common WordPress attack vectors. The vulnerability history being completely clean with zero recorded CVEs reinforces this positive outlook, indicating a stable and well-maintained codebase over time.
However, the static analysis also reveals a potential area for concern regarding output escaping. While there are outputs being processed, only 31% are properly escaped. This leaves a significant portion of output vulnerable to cross-site scripting (XSS) attacks if not handled with extreme care in the remaining unescaped portions. The lack of taint analysis results (0 flows analyzed) means that the effectiveness of the sanitization and escaping measures, particularly in complex data flows, cannot be definitively assessed. Without any identified vulnerabilities to date, the plugin has performed admirably, but the unescaped output remains a notable weakness that could be exploited.
Key Concerns
- Unescaped output is a concern
Pronamic Subscriptions Security Vulnerabilities
Pronamic Subscriptions Release Timeline
Pronamic Subscriptions Code Analysis
Output Escaping
Pronamic Subscriptions Attack Surface
WordPress Hooks 11
Maintenance & Trust
Pronamic Subscriptions Maintenance & Trust
Maintenance Signals
Community Trust
Pronamic Subscriptions Alternatives
WP LinkedIn Auto Publish
wp-linkedin-auto-publish
WP LinkedIn Auto Publish automatically publishes posts, custom posts and pages to your LinkedIn profile and/or company pages.
Pronamic Pay
pronamic-ideal
The Pronamic Pay plugin adds payment methods like iDEAL, Bancontact, credit card and more to your WordPress site for a variety of payment providers.
MAS Companies For WP Job Manager
mas-wp-job-manager-company
MAS Companies For WP Job Manager is a free plugin that allow you to manage companies from the WordPress admin panel, and allow employers to post their …
WP Job Manager – Company Profiles
wp-job-manager-companies
Outputs a list of all companies that have submitted jobs with links to their listings and profile.
Pronamic Google Maps
pronamic-google-maps
This plugin makes it easy to add Google Maps to your WordPress post, pages or other custom post types.
Pronamic Subscriptions Developer Profile
16 plugins · 5K total installs
How We Detect Pronamic Subscriptions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pronamic-subscriptions/admin/css/meta-box-subscription-details.css/wp-content/plugins/pronamic-subscriptions/admin/js/meta-box-subscription-details.js/wp-content/plugins/pronamic-subscriptions/admin/js/meta-box-subscription-details.jspronamic-subscriptions/admin/css/meta-box-subscription-details.css?ver=pronamic-subscriptions/admin/js/meta-box-subscription-details.js?ver=HTML / DOM Fingerprints
pronamic-subscription-details-wrap<!-- begin meta box subscription details --><!-- end meta box subscription details --><!-- begin meta box subscription capabilities --><!-- end meta box subscription capabilities -->+2 morename="pronamic_subscription_price"name="pronamic_subscription_role"name="pronamic_subscription_id"