
Quotepro Payment Widget Security & Risk Analysis
wordpress.org/plugins/quotepro-payment-widgetAdds the ability to accept monthy insurance, loan, rent or utility payments directly from your wordpress site
Is Quotepro Payment Widget Safe to Use in 2026?
Generally Safe
Score 85/100Quotepro Payment Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "quotepro-payment-widget" v2.0.0 plugin exhibits a mixed security posture. On one hand, the absence of known CVEs and a clean vulnerability history are positive indicators. The plugin also demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and appears to have no file operations or external HTTP requests, which reduces potential attack vectors. However, significant concerns arise from the static analysis results. The presence of a dangerous function (`create_function`) is a red flag, as it can be exploited in various ways if not handled with extreme care. More critically, a complete lack of output escaping across all identified outputs (100%) presents a high risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of any nonce checks or capability checks means that any potential entry points, even if not immediately apparent in the attack surface metrics, would be entirely unprotected against unauthorized actions. The taint analysis showing zero flows is also noteworthy; while positive in itself, it might be incomplete if the static analysis couldn't fully trace data flow, especially given the other identified code weaknesses. In conclusion, while the plugin avoids common historical vulnerabilities and uses prepared statements, the critical issues of 100% unescaped output and the use of a dangerous function, coupled with a complete lack of authorization checks, create significant security weaknesses that require immediate attention.
Key Concerns
- 100% of outputs are not properly escaped
- Dangerous function used: create_function
- No nonce checks found
- No capability checks found
Quotepro Payment Widget Security Vulnerabilities
Quotepro Payment Widget Release Timeline
Quotepro Payment Widget Code Analysis
Dangerous Functions Found
Output Escaping
Quotepro Payment Widget Attack Surface
WordPress Hooks 9
Maintenance & Trust
Quotepro Payment Widget Maintenance & Trust
Maintenance Signals
Community Trust
Quotepro Payment Widget Alternatives
Quotepro Insurance Widget
quotepro-insurance-widget
Adds the ability to provide your customers with realtime comparison insurance quotes directly from your wordpress site
Quotepro Office Widget
quotepro-office-widget
Adds the ability to locate offices directly from your wordpress site
Quomation Consumer Portal
quomation-consumer-portal
Embed the Quomation auto-quote widget on your site using your Agency ID — no code editing required.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 120+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Quotepro Payment Widget Developer Profile
3 plugins · 40 total installs
How We Detect Quotepro Payment Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quotepro-payment-widget/css/admin.css/wp-content/plugins/quotepro-payment-widget/js/admin.js/wp-content/plugins/quotepro-payment-widget/js/admin.jsquotepro-payment-widget/css/admin.css?ver=quotepro-payment-widget/js/admin.js?ver=HTML / DOM Fingerprints
quotepro-payment-widget-classdata-quotepro-widget-iddata-quotepro-widget-urldata-quotepro-widget-affdata-quotepro-widget-langdata-quotepro-widget-autodata-quotepro-widget-cycle<div class="quotepro-payment-widget-class">