
Subscription ePayco Security & Risk Analysis
wordpress.org/plugins/subscription-epaycoReceive recurring payments
Is Subscription ePayco Safe to Use in 2026?
Generally Safe
Score 85/100Subscription ePayco has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subscription-epayco" plugin version 4.0.2 exhibits a concerning security posture due to its unprotected entry points. While the plugin demonstrates good practices in other areas, such as avoiding dangerous functions, utilizing prepared statements for most SQL queries, and having no recorded vulnerabilities, the presence of three AJAX handlers without any authentication or capability checks is a significant risk. This directly exposes these handlers to potential abuse by unauthenticated users, which could lead to various forms of attacks depending on their functionality.
The code analysis reveals a notable weakness in output escaping, with only 35% of outputs being properly escaped. This, combined with the unprotected AJAX endpoints, increases the likelihood of cross-site scripting (XSS) vulnerabilities. Despite the absence of critical taint flows and a clean vulnerability history, the unprotected entry points and insufficient output escaping represent the most immediate threats. A robust security strategy would prioritize securing these AJAX handlers and improving output sanitization to mitigate these risks.
Key Concerns
- AJAX handlers without auth checks
- Low output escaping percentage
- Missing capability checks on AJAX
Subscription ePayco Security Vulnerabilities
Subscription ePayco Code Analysis
SQL Query Safety
Output Escaping
Subscription ePayco Attack Surface
AJAX Handlers 3
WordPress Hooks 20
Maintenance & Trust
Subscription ePayco Maintenance & Trust
Maintenance Signals
Community Trust
Subscription ePayco Alternatives
Payment Integration Wompi
payment-integration-wompi
Integration of Wompi for Woocommerce
Payment Integration Wompi – El Salvador
wompi-el-salvador
Integración para Wompi - El Salvador para Woocommerce
Pay with ATH Movil (WooCommerce payment gateway)
pay-with-ath-movil-woocommerce-gateway
Accept ATH Movil payments on your WooCommerce store.
Shipping Servientrega Woocommerce
shipping-servientrega-woocommerce
Servientrega empresa transportadora de Colombia
Subscription Payu Latam
subscription-payu-latam
Receive recurring payments for the countries Brazil, Colombia, Mexico and Peru
Subscription ePayco Developer Profile
11 plugins · 8K total installs
How We Detect Subscription ePayco
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subscription-epayco/assets/js/sweetalert2.js/wp-content/plugins/subscription-epayco/assets/js/subscription-epayco-config.js/wp-content/plugins/subscription-epayco/assets/js/sweetalert2.js/wp-content/plugins/subscription-epayco/assets/js/subscription-epayco-config.jssubscription-epayco/assets/js/sweetalert2.js?ver=subscription-epayco/assets/js/subscription-epayco-config.js?ver=HTML / DOM Fingerprints
subscriptionepayco