Events Manager Pro – Payment Gateway Selector Security & Risk Analysis

wordpress.org/plugins/stonehenge-em-gateway-selector

Easily set or unset your activated payment gateway(s) per individual single event in Event Manager Pro with a simple checkbox.

20 active installs v2.0.4 PHP 7.3+ WP 5.5+ Updated Unknown
events-managergatewaymolliepayment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Events Manager Pro – Payment Gateway Selector Safe to Use in 2026?

Generally Safe

Score 100/100

Events Manager Pro – Payment Gateway Selector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "stonehenge-em-gateway-selector" plugin v2.0.4 exhibits a generally strong security posture based on the provided static analysis. The plugin has a zero attack surface, meaning there are no directly exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no identified dangerous functions, raw SQL queries, file operations, or external HTTP requests, all of which are positive indicators. The presence of a nonce check and the use of prepared statements for SQL queries demonstrate good development practices. However, a weakness lies in the output escaping, with only 67% of outputs being properly escaped, suggesting a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled rigorously across all output points.

The lack of any recorded vulnerabilities or CVEs, combined with the clean taint analysis, further reinforces the impression of a secure plugin. This history indicates a commitment to security or simply a lack of past exploitable issues. The absence of capability checks is a minor concern, especially if any of the unescaped outputs are used in a context where sensitive information could be displayed. Overall, the plugin is well-developed from a security perspective, with the primary area for improvement being the consistent and complete escaping of all outputs.

Key Concerns

  • Output escaping is not fully implemented
Vulnerabilities
None known

Events Manager Pro – Payment Gateway Selector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Events Manager Pro – Payment Gateway Selector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped9 total outputs
Attack Surface

Events Manager Pro – Payment Gateway Selector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitstonehenge-em-gateway-selector.php:53
filterplugin_row_metastonehenge-em-gateway-selector.php:54
actionem_events_admin_bookings_footerstonehenge-em-gateway-selector.php:57
filterem_event_validate_metastonehenge-em-gateway-selector.php:58
actionsave_poststonehenge-em-gateway-selector.php:59
actionem_booking_form_footerstonehenge-em-gateway-selector.php:60
actionplugins_loadedstonehenge-em-gateway-selector.php:208
Maintenance & Trust

Events Manager Pro – Payment Gateway Selector Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version7.3
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Events Manager Pro – Payment Gateway Selector Developer Profile

Stonehenge Creations

9 plugins · 1K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Events Manager Pro – Payment Gateway Selector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
em-gateway-selector
Data Attributes
name="_em_active_gateways[]"id="em-gateway-selector"
FAQ

Frequently Asked Questions about Events Manager Pro – Payment Gateway Selector