
Events Manager Pro – Mollie Payments Security & Risk Analysis
wordpress.org/plugins/stonehenge-em-mollieAdd 18 payment methods and 31 currencies in one go! This is the only payment add-on for Events Manager that adds more than 2 payment methods to your w …
Is Events Manager Pro – Mollie Payments Safe to Use in 2026?
Generally Safe
Score 85/100Events Manager Pro – Mollie Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'stonehenge-em-mollie' plugin version 2.4.4 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded for this plugin, and the static analysis indicates no direct exposure of dangerous functions, raw SQL queries, file operations, or external HTTP requests. The absence of AJAX handlers and REST API routes without proper authentication checks is also a strong indicator of good security practices in those areas. However, the code analysis reveals significant concerns regarding output escaping and unsanitized data flows. A concerning 75% of output operations are not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified two flows with unsanitized paths, which could potentially lead to data manipulation or unauthorized access if these paths are exposed through the defined entry points. The lack of nonce checks and capability checks on the identified entry points (shortcodes) is a critical oversight, as it means these shortcodes are accessible and potentially exploitable by any authenticated user, regardless of their role or permissions. While the plugin has no vulnerability history, this can be a double-edged sword; it might indicate diligent security practices, or it could simply mean the plugin hasn't been extensively scrutinized or targeted. The combination of unescaped output and unsanitized data flows, coupled with a lack of robust authorization on its entry points, presents a moderate to high risk.
Key Concerns
- Unsanitized paths in taint analysis (2 flows)
- Insufficient output escaping (75% unescaped)
- No nonce checks on entry points (shortcodes)
- No capability checks on entry points (shortcodes)
- Bundled library 'Guzzle' potential for outdated version
Events Manager Pro – Mollie Payments Security Vulnerabilities
Events Manager Pro – Mollie Payments Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Events Manager Pro – Mollie Payments Attack Surface
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
Events Manager Pro – Mollie Payments Maintenance & Trust
Maintenance Signals
Community Trust
Events Manager Pro – Mollie Payments Alternatives
GF Mollie by Indigo
gf-mollie-by-indigo
You can link Mollie to Gravity Forms with GF Mollie by Indigo.
Doneren met Mollie
doneren-met-mollie
This plugin is both suitable for one-time donations and for periodic payments. All payment methods of Mollie are integrated into the plugin.
Paytium: Mollie payment forms & donations
paytium
Mollie forms for payments and donations. With iDEAL | WERO , PayPal, Credit/Debet cards, subscriptions and recurring payments!
YabandPay For WooCommerce
yabandpay-for-woocommerce
YabandPay B.V. (YabandPay)是一家持有荷兰中央银行(De Nederlandsche Bank, DNB)支付许可并受其监管的创新支付机构。目前,我们正在为来自30个EEA国家和瑞士的商家提供线上/线下的本地和跨境支付解决方案,涵盖了购物、电商、旅游、教育、政府机构、餐饮等多 …
q-invoice Mollie iDeal for Gravity Forms
qinvoice-mollie-ideal-for-gravity-forms
Adds Mollie iDeal and other payment methods to your Gravity Forms.
Events Manager Pro – Mollie Payments Developer Profile
9 plugins · 1K total installs
How We Detect Events Manager Pro – Mollie Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stonehenge-em-mollie/assets/stonehenge-em-mollie.min.js/wp-content/plugins/stonehenge-em-mollie/assets/stonehenge-em-mollie.min.css/wp-content/plugins/stonehenge-em-mollie/assets/stonehenge-em-mollie.min.jsstonehenge-em-mollie/assets/stonehenge-em-mollie.min.js?ver=stonehenge-em-mollie/assets/stonehenge-em-mollie.min.css?ver=HTML / DOM Fingerprints
mollie_methods[mollie_methods][mollie-methods]