
SmartPay Security & Risk Analysis
wordpress.org/plugins/smartpaySell digital downloads and accept payments including donations easily with Stripe, PayPal, Paddle etc. - simple, fast, and secure.
Is SmartPay Safe to Use in 2026?
Generally Safe
Score 97/100SmartPay has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'smartpay' plugin v2.8.2 presents a mixed security posture. While the code analysis shows a good percentage of SQL queries using prepared statements and properly escaped outputs, a significant concern is the large number of unprotected REST API routes (12 out of 12). This creates a substantial attack surface that could be exploited for unauthorized actions or information disclosure. The taint analysis, though limited in scope, did not reveal any critical or high-severity unsanitized paths, which is a positive sign. However, the plugin's vulnerability history is concerning, with two known CVEs, including a past high-severity vulnerability related to authorization bypass and sensitive information exposure. The fact that there are currently no unpatched CVEs is a strength, but the historical pattern of such vulnerabilities suggests potential for recurring issues in these areas, especially if the underlying code logic is not robustly secured against common attack vectors.
Key Concerns
- 12 unprotected REST API routes
- Past High Severity CVE
- Past Medium Severity CVE
- 5 unsanitized flows (taint analysis)
SmartPay Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP SmartPay <= 2.7.13 - Authenticated (Subscriber+) Account Takeover
Download Manager and Payment Form WordPress Plugin – WP SmartPay 1.1.0 - 2.7.13 - Authenticated (Subscriber+) Information Exposure
SmartPay Release Timeline
SmartPay Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SmartPay Attack Surface
AJAX Handlers 1
REST API Routes 12
Shortcodes 4
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
SmartPay Maintenance & Trust
Maintenance Signals
Community Trust
SmartPay Alternatives
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Download Monitor
download-monitor
Powerful Download Manager Plugin for WordPress
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
easy-digital-downloads
The #1 eCommerce plugin to sell digital products & subscriptions. Accept payments with Stripe & PayPal. Sell ebooks, software & more.
Premium Packages – Sell Digital Products Securely
wpdm-premium-packages
Premium Packages is a free, full-featured WordPress eCommerce plugin to sell digital products easily and securely.
Gravity Forms Eway
gravityforms-eway
Easily create online payment forms with Gravity Forms and Eway.
SmartPay Developer Profile
3 plugins · 2K total installs
How We Detect SmartPay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smartpay/public/css/admin.css/wp-content/plugins/smartpay/public/js/admin.js/wp-content/plugins/smartpay/public/js/admin.jssmartpay/public/css/admin.css?ver=smartpay/public/js/admin.js?ver=HTML / DOM Fingerprints
smartpay-svg-icondata-sp-admin-pagedata-sp-form-builder-pagedata-sp-settings-pagedata-sp-integrations-pagesmartpay/wp-json/smartpay/