
Subscription Manager for Stripe Security & Risk Analysis
wordpress.org/plugins/subscription-manager-for-stripeThe only WordPress subscription plugin with 0% transaction fees, usage-based billing, and full Stripe-native integration. Built for SaaS founders and …
Is Subscription Manager for Stripe Safe to Use in 2026?
Generally Safe
Score 100/100Subscription Manager for Stripe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'subscription-manager-for-stripe' plugin v2.2.3 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all detected output being properly escaped. The absence of dangerous functions, file operations, and critical or high severity taint analysis flows are significant strengths. The plugin also appears to have a robust approach to authentication and authorization, with a high number of nonce and capability checks relative to its entry points.
However, a notable concern lies within the REST API routes. While there are two routes in total, one of them lacks a proper permission callback, creating a potential access control vulnerability. This unprotected entry point is the primary risk identified in the static analysis. The plugin's vulnerability history is currently clean, with no recorded CVEs, which is a positive indicator. This suggests a history of secure development or effective patching if vulnerabilities have existed.
In conclusion, the plugin is well-developed with strong foundations in secure coding. The presence of a single unprotected REST API route is the most significant weakness and requires immediate attention. The lack of any historical vulnerabilities is reassuring, but the identified unprotected entry point warrants a cautious approach until it is addressed.
Key Concerns
- REST API route without permission callback
Subscription Manager for Stripe Security Vulnerabilities
Subscription Manager for Stripe Release Timeline
Subscription Manager for Stripe Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Subscription Manager for Stripe Attack Surface
AJAX Handlers 4
REST API Routes 2
Shortcodes 1
WordPress Hooks 41
Scheduled Events 2
Maintenance & Trust
Subscription Manager for Stripe Maintenance & Trust
Maintenance Signals
Community Trust
Subscription Manager for Stripe Alternatives
Memberful – Membership Plugin
memberful-wp
Sell memberships and restrict access to content with WordPress and Memberful.
CashFlow Subscriptions
cashflow-subscriptions
Simple, modern Stripe subscriptions for WordPress. Create paywalls, manage members, and restrict content without WooCommerce or heavy plugins.
WE Subscription
we-subscription
Sell your simple and variable products with recurring payments without bloat.
Pay with Vipps and MobilePay for WooCommerce
woo-vipps
Official Vipps MobilePay payment plugin for WooCommerce.
Recurio – Ultimate Subscription for WooCommerce
recurio
A powerful and comprehensive WooCommerce subscription management plugin with advanced analytics, automated billing, and customer portal.
Subscription Manager for Stripe Developer Profile
1 plugin · 0 total installs
How We Detect Subscription Manager for Stripe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subscription-manager-for-stripe/assets/css/admin-style.css/wp-content/plugins/subscription-manager-for-stripe/assets/css/frontend-style.css/wp-content/plugins/subscription-manager-for-stripe/assets/js/checkout.js/wp-content/plugins/subscription-manager-for-stripe/assets/js/stripe-checkout.js/wp-content/plugins/subscription-manager-for-stripe/assets/js/admin.js/wp-content/plugins/subscription-manager-for-stripe/assets/js/checkout.js/wp-content/plugins/subscription-manager-for-stripe/assets/js/stripe-checkout.js/wp-content/plugins/subscription-manager-for-stripe/assets/js/admin.jssubscription-manager-for-stripe/assets/css/admin-style.css?ver=subscription-manager-for-stripe/assets/css/frontend-style.css?ver=subscription-manager-for-stripe/assets/js/checkout.js?ver=subscription-manager-for-stripe/assets/js/stripe-checkout.js?ver=subscription-manager-for-stripe/assets/js/admin.js?ver=HTML / DOM Fingerprints
strp-sub-formdata-plugin-versionstrp_sub_fs