
SubscriptionFlow Add-On for Paywall Security & Risk Analysis
wordpress.org/plugins/subscriptionflow-add-on-for-paywallSubscriptionFlow Add-On for Paywall is a powerful tool for managing content access restrictions based on user subscriptions.
Is SubscriptionFlow Add-On for Paywall Safe to Use in 2026?
Generally Safe
Score 92/100SubscriptionFlow Add-On for Paywall has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subscriptionflow-add-on-for-paywall" plugin version 1.0.8 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in SQL query handling, with 100% of queries utilizing prepared statements, and a high percentage (91%) of output escaping. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, suggesting a potentially stable and well-maintained codebase historically.
However, significant concerns arise from the static analysis. The plugin presents a considerable attack surface with 9 total entry points, 5 of which are unprotected. Specifically, 3 out of 5 AJAX handlers lack authentication checks, and both REST API routes are missing permission callbacks. While taint analysis shows no critical or high severity unsanitized paths, the presence of 4 flows with unsanitized paths, even if deemed lower severity, combined with the numerous unprotected entry points, creates a substantial risk of unauthorized access or manipulation. The file operations and external HTTP requests also warrant careful scrutiny in relation to these unprotected entry points.
In conclusion, while the plugin avoids common pitfalls like raw SQL and outdated bundled libraries, its substantial number of unprotected AJAX handlers and REST API routes represents a clear and present danger. The lack of proper authentication and authorization on these entry points could allow unauthenticated users to trigger potentially harmful actions. Future development should prioritize securing these exposed endpoints to significantly improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- REST API routes without permission callbacks
- Flows with unsanitized paths
- File operations
- External HTTP requests
SubscriptionFlow Add-On for Paywall Security Vulnerabilities
SubscriptionFlow Add-On for Paywall Release Timeline
SubscriptionFlow Add-On for Paywall Code Analysis
Output Escaping
Data Flow Analysis
SubscriptionFlow Add-On for Paywall Attack Surface
AJAX Handlers 5
REST API Routes 2
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
SubscriptionFlow Add-On for Paywall Maintenance & Trust
Maintenance Signals
Community Trust
SubscriptionFlow Add-On for Paywall Alternatives
Memberful – Membership Plugin
memberful-wp
Sell memberships and restrict access to content with WordPress and Memberful.
Leaky Paywall
leaky-paywall
The subscription engine for news & niche publishers.
ChamaWP – Monetize With Donations, Memberships, Crowdfunding, Commissions & Restricted Content
chama
💳 A WordPress plugin for monetizing your tribe! 🚀
Chargely Free Subscriptions For Woocommernce
chargely-free-subscriptions-for-woocommerce
Start your Subscription Business in minutes with Chargely. Chargely provides PCI Certified Payment page for your card processing. So that you don't need a PCI Certification.
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!
SubscriptionFlow Add-On for Paywall Developer Profile
2 plugins · 0 total installs
How We Detect SubscriptionFlow Add-On for Paywall
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subscriptionflow-add-on-for-paywall/admin/js/pw-sf-admin-script.js/wp-content/plugins/subscriptionflow-add-on-for-paywall/admin/css/wc-sf-custom-style.css/wp-content/plugins/subscriptionflow-add-on-for-paywall/front-end/js/pw-sf-frontend-custom-script.jsadmin/js/pw-sf-admin-script.jsfront-end/js/pw-sf-frontend-custom-script.jspw-sf-admin-script.js?v=wc-sf-custom-style.css?v=pw-sf-frontend-custom-script.js?v=HTML / DOM Fingerprints
pw_sf_ajax_objajax_login_object/wp-json/api/sf-pw-create-update-user