
Razorpay Subscription Button Elementor Plugin Security & Risk Analysis
wordpress.org/plugins/razorpay-subscription-button-elementorA very simple elementor widget block native to the wordpress that lets you add a convenient button on your wordpress page.
Is Razorpay Subscription Button Elementor Plugin Safe to Use in 2026?
Generally Safe
Score 91/100Razorpay Subscription Button Elementor Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "razorpay-subscription-button-elementor" plugin v1.0.5 exhibits a generally good security posture based on the static analysis, with a notable absence of dangerous functions, file operations, external HTTP requests, and SQL queries not using prepared statements. The high percentage of properly escaped output is also a positive sign. However, the static analysis did reveal a concerning pattern in the taint analysis: all four analyzed flows had unsanitized paths. While no critical or high severity issues were found here, this indicates a potential for vulnerabilities if user-supplied data is not handled rigorously throughout the application.
The vulnerability history for this plugin shows one known CVE, which was a medium severity Cross-Site Scripting (XSS) vulnerability. The fact that it is listed as currently unpatched, despite the last vulnerability being recorded in the future (2025-03-04), is highly unusual and likely an artifact of the data source. Nevertheless, past XSS vulnerabilities suggest that improper input neutralization could be a recurring theme. The plugin's strengths lie in its well-managed SQL and output handling, but the taint analysis and historical XSS indicates a need for increased vigilance regarding input sanitization and potential XSS risks.
Key Concerns
- Taint flows with unsanitized paths
- Medium severity vulnerability history
- No capability checks found
- No nonce checks found
Razorpay Subscription Button Elementor Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Razorpay Subscription Button Elementor Plugin <= 1.0.3 - Reflected Cross-Site Scripting via add_query_arg and remove_query_arg Functions
Razorpay Subscription Button Elementor Plugin Code Analysis
Output Escaping
Data Flow Analysis
Razorpay Subscription Button Elementor Plugin Attack Surface
WordPress Hooks 5
Maintenance & Trust
Razorpay Subscription Button Elementor Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Razorpay Subscription Button Elementor Plugin Alternatives
Razorpay for Gravity Forms
razorpay-gravity-forms
Allows you to use Razorpay payment gateway with the gravity forms plugin.
Razorpay Subscriptions for WooCommerce
razorpay-subscriptions-for-woocommerce
Allows you to use Razorpay payment gateway with the WooCommerce Subscriptions plugin. This requires Subscriptions feature to be enabled for your accou …
Razorpay Subscription Button Plugin
razorpay-subscription-button
A very simple block native to the wordpress that lets you add a convenient button on your wordpress page. This block is like any other wordpress plugi …
Razorpay for WooCommerce
woo-razorpay
Start accepting payments in minutes with 100% digital onboarding & feature filled Razorpay payment gateway with the WooCommerce plugin.
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple to use, all-in-one platform, that anyone can set up in just a few minutes!
Razorpay Subscription Button Elementor Plugin Developer Profile
10 plugins · 107K total installs
How We Detect Razorpay Subscription Button Elementor Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/razorpay-subscription-button-elementor/public/css/button.css/wp-content/plugins/razorpay-subscription-button-elementor/public/css/bootstrap.min.cssrazorpay-subscription-button-elementor/public/css/button.css?ver=razorpay-subscription-button-elementor/public/css/bootstrap.min.css?ver=HTML / DOM Fingerprints
razorpay-sub-button<!-- This is the RZP Subscription button loader class. --><!-- Adding constants --><!-- admin-post.php is a file that contains methods for us to process HTTP requests --><!-- Creating the menu for plugin after load -->+5 moredata-razorpay-linkdata-razorpay-textdata-razorpay-button-iddata-razorpay-themedata-razorpay-button-typedata-razorpay-button-type-id