SecurePay For Fluent Forms Security & Risk Analysis

wordpress.org/plugins/securepay-for-fluentforms

SecurePay payment platform plugin for Fluent Forms.

20 active installs v1.0.5 PHP 7.2+ WP 5.4+ Updated Sep 6, 2023
fpxmalaysiaonline-bankingpayment-gatewaypayment-platform
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SecurePay For Fluent Forms Safe to Use in 2026?

Generally Safe

Score 85/100

SecurePay For Fluent Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "securepay-for-fluentforms" plugin v1.0.5 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping all output. The absence of dangerous functions, file operations, and critical or high-severity taint flows is also highly encouraging. Furthermore, the plugin has no recorded vulnerabilities, CVEs, or past incidents, suggesting a history of responsible development.

However, there are a few areas that warrant attention. The presence of two flows with unsanitized paths in the taint analysis, while not classified as critical or high, indicates a potential for insecure handling of user-supplied data that could be exploited under specific circumstances. Additionally, the plugin performs one external HTTP request, which can be a vector for supply chain attacks if the target endpoint is compromised or misconfigured. The single capability check is also a minimal safeguard, and while there are no immediate threats identified from the static analysis, robust input validation and sanitization should always be a priority, especially around external interactions and any data that could influence program flow.

In conclusion, the plugin has a solid foundation of secure coding, with excellent SQL and output handling. The lack of historical vulnerabilities is a positive sign. The primary concerns lie in the two unsanitized taint flows and the single external HTTP request, which, while not critical based on the severity classification, represent potential areas for future security enhancements and careful monitoring.

Key Concerns

  • Unsanitized taint flows found
  • External HTTP request present
Vulnerabilities
None known

SecurePay For Fluent Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SecurePay For Fluent Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
25 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped25 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
init (includes\src\SecurePayProcessor.php:23)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SecurePay For Fluent Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes\src\SecurePayFluentForms.php:16
actionplugins_loadedincludes\src\SecurePayFluentForms.php:31
actionall_admin_noticesincludes\src\SecurePayFluentForms.php:35
actionfluentform_loadedincludes\src\SecurePayFluentForms.php:41
filterauto_update_pluginincludes\src\SecurePayFluentForms.php:58
filterfluentformpro_available_payment_methodsincludes\src\SecurePayHandler.php:32
actionfluentform_scripts_registeredincludes\src\SecurePayProcessor.php:39
filterfluentform_rendering_field_html_payment_methodincludes\src\SecurePayProcessor.php:46
filterfluentform_rendering_field_html_buttonincludes\src\SecurePayProcessor.php:60
actionwpincludes\src\SecurePayProcessor.php:71
actioninitincludes\src\SecurePayProcessor.php:84
Maintenance & Trust

SecurePay For Fluent Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 6, 2023
PHP min version7.2
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

SecurePay For Fluent Forms Developer Profile

SecurePay

8 plugins · 260 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SecurePay For Fluent Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/securepay-for-fluentforms/securepay-for-fluentforms.php/wp-content/plugins/securepay-for-fluentforms/includes/load.php/wp-content/plugins/securepay-for-fluentforms/includes/src/SecurePayProcessor.php
Version Parameters
securepay-for-fluentforms/securepay-for-fluentforms.php?ver=securepay-for-fluentforms/includes/load.php?ver=securepay-for-fluentforms/includes/src/SecurePayProcessor.php?ver=

HTML / DOM Fingerprints

CSS Classes
spffm-bank-list
Data Attributes
data-securepayffm-target
JS Globals
SecurePayFluentForms
Shortcode Output
[securepay_payment_form]
FAQ

Frequently Asked Questions about SecurePay For Fluent Forms