
SecurePay For GiveWP Security & Risk Analysis
wordpress.org/plugins/securepay-for-givewpSecurePay payment platform plugin for GiveWP.
Is SecurePay For GiveWP Safe to Use in 2026?
Generally Safe
Score 85/100SecurePay For GiveWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'securepay-for-givewp' plugin version 1.0.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent adherence to secure coding practices, with no dangerous functions, fully prepared SQL statements, and all output properly escaped. Furthermore, the complete absence of known CVEs and a zero-day vulnerability history indicates a mature and well-maintained codebase.
While the plugin's attack surface appears to be non-existent from the provided entry point analysis (0 AJAX, REST, shortcodes, and cron events), this also means there are no immediate exploitable vectors visible. The presence of file operations and an external HTTP request warrants careful review in a more dynamic analysis, though they are not flagged as issues here. The absence of nonce checks and only a single capability check across the entire codebase, coupled with the bundled Select2 library, represent minor areas for potential future improvement and vigilance.
Overall, this plugin appears to be highly secure, with a strong foundation in defensive coding. The lack of any vulnerabilities, past or present, is a significant strength. The minimal deductions are based on general best practices and potential, albeit unproven, areas of concern. Continued vigilance with updates and code reviews is always recommended, but the current data suggests a low-risk plugin.
Key Concerns
- No nonce checks detected
- Only one capability check detected
- Bundled library (Select2) may be outdated
SecurePay For GiveWP Security Vulnerabilities
SecurePay For GiveWP Code Analysis
Bundled Libraries
Output Escaping
SecurePay For GiveWP Attack Surface
WordPress Hooks 15
Maintenance & Trust
SecurePay For GiveWP Maintenance & Trust
Maintenance Signals
Community Trust
SecurePay For GiveWP Alternatives
SecurePay For WooCommerce
securepay
SecurePay payment platform plugin for WooCommerce.
SecurePay For Fluent Forms
securepay-for-fluentforms
SecurePay payment platform plugin for Fluent Forms.
SecurePay For GravityForms
securepay-for-gravityforms
SecurePay payment platform plugin for Gravity Forms.
SecurePay For Paid Memberships Pro
securepay-for-paidmembershipspro
SecurePay payment platform plugin for Paid Memberships Pro.
SecurePay For WPForms
securepay-for-wpforms
SecurePay payment platform plugin for WPForms.
SecurePay For GiveWP Developer Profile
8 plugins · 260 total installs
How We Detect SecurePay For GiveWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/securepay-for-givewp/includes/admin/assets/css/securepay-admin.css/wp-content/plugins/securepay-for-givewp/includes/assets/js/securepay.js/wp-content/plugins/securepay-for-givewp/includes/assets/js/securepay.jssecurepay-for-givewp/includes/admin/assets/css/securepay-admin.css?ver=securepay-for-givewp/includes/assets/js/securepay.js?ver=HTML / DOM Fingerprints
securepay-admin-settings-wrapsecurepay-payment-wrapThis file served as a wrapper to solve the issue with the X-Frame-Options header.This file will receive input from GiveWP_SecurePay::process_payment() and send the payment data to the SecurePay end-point.The input should send as $_GET query and not as HTML form.References:+1 moredata-securepay-testmodedata-securepay-banklistdata-securepay-banklogodata-securepay-live-tokendata-securepay-live-checksumdata-securepay-sandbox-token+2 moresecurepay_params