Events Manager Pro – Mollie Payments Security & Risk Analysis

wordpress.org/plugins/stonehenge-em-mollie

Add 18 payment methods and 31 currencies in one go! This is the only payment add-on for Events Manager that adds more than 2 payment methods to your w …

70 active installs v2.4.4 PHP 7.3+ WP 5.3+ Updated Aug 7, 2020
bancontactevents-manageridealmolliesofort
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Events Manager Pro – Mollie Payments Safe to Use in 2026?

Generally Safe

Score 85/100

Events Manager Pro – Mollie Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'stonehenge-em-mollie' plugin version 2.4.4 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded for this plugin, and the static analysis indicates no direct exposure of dangerous functions, raw SQL queries, file operations, or external HTTP requests. The absence of AJAX handlers and REST API routes without proper authentication checks is also a strong indicator of good security practices in those areas. However, the code analysis reveals significant concerns regarding output escaping and unsanitized data flows. A concerning 75% of output operations are not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified two flows with unsanitized paths, which could potentially lead to data manipulation or unauthorized access if these paths are exposed through the defined entry points. The lack of nonce checks and capability checks on the identified entry points (shortcodes) is a critical oversight, as it means these shortcodes are accessible and potentially exploitable by any authenticated user, regardless of their role or permissions. While the plugin has no vulnerability history, this can be a double-edged sword; it might indicate diligent security practices, or it could simply mean the plugin hasn't been extensively scrutinized or targeted. The combination of unescaped output and unsanitized data flows, coupled with a lack of robust authorization on its entry points, presents a moderate to high risk.

Key Concerns

  • Unsanitized paths in taint analysis (2 flows)
  • Insufficient output escaping (75% unescaped)
  • No nonce checks on entry points (shortcodes)
  • No capability checks on entry points (shortcodes)
  • Bundled library 'Guzzle' potential for outdated version
Vulnerabilities
None known

Events Manager Pro – Mollie Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Events Manager Pro – Mollie Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

25% escaped12 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
update (includes\class-gateway.php:497)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Events Manager Pro – Mollie Payments Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[mollie_methods] includes\class-functions.php:22
[mollie-methods] includes\class-functions.php:23
WordPress Hooks 12
actionadmin_noticesincludes\class-functions.php:17
filterem_mollie_wildcardsincludes\class-functions.php:18
filterem_event_output_placeholderincludes\class-functions.php:19
actioninitincludes\class-functions.php:24
actionem_gateway_jsincludes\class-gateway.php:40
filterem_booking_validateincludes\class-gateway.php:41
filterthe_contentincludes\class-gateway.php:43
actioninitstonehenge-em-mollie.php:30
actionadmin_enqueue_scriptsstonehenge-em-mollie.php:31
filterplugin_action_linksstonehenge-em-mollie.php:32
filterplugin_row_metastonehenge-em-mollie.php:33
actionplugins_loadedstonehenge-em-mollie.php:111
Maintenance & Trust

Events Manager Pro – Mollie Payments Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 7, 2020
PHP min version7.3
Downloads5K

Community Trust

Rating100/100
Number of ratings5
Active installs70
Developer Profile

Events Manager Pro – Mollie Payments Developer Profile

Stonehenge Creations

9 plugins · 1K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Events Manager Pro – Mollie Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stonehenge-em-mollie/assets/stonehenge-em-mollie.min.js/wp-content/plugins/stonehenge-em-mollie/assets/stonehenge-em-mollie.min.css
Script Paths
/wp-content/plugins/stonehenge-em-mollie/assets/stonehenge-em-mollie.min.js
Version Parameters
stonehenge-em-mollie/assets/stonehenge-em-mollie.min.js?ver=stonehenge-em-mollie/assets/stonehenge-em-mollie.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
mollie_methods
Shortcode Output
[mollie_methods][mollie-methods]
FAQ

Frequently Asked Questions about Events Manager Pro – Mollie Payments