Vandar Payment Gateway for Paid Memberships Pro Security & Risk Analysis

wordpress.org/plugins/vandar-paid-memberships-pro

Vandar payment method for Paid Memberships Pro.

0 active installs v2.1.2 PHP + WP + Updated Aug 10, 2023
gatewaymembershipspaid-memberships-prorestrict-contentvandar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Vandar Payment Gateway for Paid Memberships Pro Safe to Use in 2026?

Generally Safe

Score 85/100

Vandar Payment Gateway for Paid Memberships Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "vandar-paid-memberships-pro" plugin version 2.1.2 presents several security concerns, primarily due to unprotected entry points. The static analysis reveals two AJAX handlers that lack authentication checks, creating a significant attack surface. While the plugin demonstrates good practices in output escaping and avoids dangerous functions or file operations, the absence of capability checks and nonce validation on AJAX endpoints is a critical oversight. The plugin's clean vulnerability history with zero known CVEs is a positive sign, suggesting a generally stable codebase and diligent maintenance regarding known vulnerabilities. However, this does not mitigate the risks posed by the identified unprotected entry points. The lack of taint analysis data is also a limitation, meaning potential vulnerabilities related to data flow were not assessed. Overall, the plugin has a potentially weak security posture concerning its exposed AJAX functionality, despite a good track record for known CVEs.

Key Concerns

  • AJAX handlers without auth checks
  • No nonce checks on AJAX handlers
  • No capability checks
  • SQL queries without prepared statements
Vulnerabilities
None known

Vandar Payment Gateway for Paid Memberships Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vandar Payment Gateway for Paid Memberships Pro Release Timeline

v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Vandar Payment Gateway for Paid Memberships Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

89% escaped9 total outputs
Attack Surface
2 unprotected

Vandar Payment Gateway for Paid Memberships Pro Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_vandar-insvandar-paid-memberships-pro.php:82
authwp_ajax_vandar-insvandar-paid-memberships-pro.php:86
WordPress Hooks 11
actioninitvandar-paid-memberships-pro.php:28
actionplugins_loadedvandar-paid-memberships-pro.php:31
actionplugins_loadedvandar-paid-memberships-pro.php:32
filterpmpro_gatewaysvandar-paid-memberships-pro.php:46
filterpmpro_payment_optionsvandar-paid-memberships-pro.php:52
filterpmpro_payment_option_fieldsvandar-paid-memberships-pro.php:56
filterpmpro_currenciesvandar-paid-memberships-pro.php:62
filterpmpro_checkout_before_change_membership_levelvandar-paid-memberships-pro.php:70
filterpmpro_include_billing_address_fieldsvandar-paid-memberships-pro.php:74
filterpmpro_include_payment_information_fieldsvandar-paid-memberships-pro.php:75
filterpmpro_required_billing_fieldsvandar-paid-memberships-pro.php:76
Maintenance & Trust

Vandar Payment Gateway for Paid Memberships Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.0
Last updatedAug 10, 2023
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Vandar Payment Gateway for Paid Memberships Pro Developer Profile

Vandar

5 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vandar Payment Gateway for Paid Memberships Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vandar-paid-memberships-pro/vandar-paid-memberships-pro.php

HTML / DOM Fingerprints

CSS Classes
gateway_vandar
Data Attributes
vandar_api_key
REST Endpoints
/wp-json/vandar-paid-memberships-pro
FAQ

Frequently Asked Questions about Vandar Payment Gateway for Paid Memberships Pro