
Wallkit Subscriptions & Paywall Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/wallkitA Plug & Play paid-content system to manage subscribers, gather fees and drive additional content sales.
Is Wallkit Subscriptions & Paywall Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 92/100Wallkit Subscriptions & Paywall Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Wallkit plugin v3.4.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, showing a high percentage of properly escaped outputs, and avoiding file operations and external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history is also a significant strength, suggesting a history of stable and secure development. However, several areas raise concern. The plugin exposes six AJAX handlers without any authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the presence of the `unserialize` function, while not directly linked to a vulnerability in this analysis, is a known risky function that can lead to serious security issues if not handled with extreme caution and proper input validation. The lack of capability checks on any of its entry points is another significant oversight that could allow unauthorized users to trigger actions they shouldn't have access to. The taint analysis showing zero flows is good, but the overall risk is elevated by the known insecure code patterns and lack of proper authorization checks.
Key Concerns
- Unprotected AJAX handlers
- Presence of unserialize function
- No capability checks on entry points
Wallkit Subscriptions & Paywall Plugin for WordPress Security Vulnerabilities
Wallkit Subscriptions & Paywall Plugin for WordPress Code Analysis
Dangerous Functions Found
Output Escaping
Wallkit Subscriptions & Paywall Plugin for WordPress Attack Surface
AJAX Handlers 6
Shortcodes 12
WordPress Hooks 35
Scheduled Events 2
Maintenance & Trust
Wallkit Subscriptions & Paywall Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Wallkit Subscriptions & Paywall Plugin for WordPress Alternatives
Memberful – Membership Plugin
memberful-wp
Sell memberships and restrict access to content with WordPress and Memberful.
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
paid-member-subscriptions
Feature-packed membership plugin for creating subscription plans, adding recurring payments & content restriction on your membership site.
Pay with Vipps and MobilePay for WooCommerce
woo-vipps
Official Vipps MobilePay payment plugin for WooCommerce.
Subscriptions & Memberships for PayPal
subscriptions-memberships-for-paypal
A simple and easy way to sell subscriptions and / or memberships with PayPal. No Coding Required. Official PayPal Partner.
Recurio – Ultimate Subscription Plugin for WooCommerce
recurio
A powerful and comprehensive WooCommerce subscription management plugin with advanced analytics, automated billing, and customer portal.
Wallkit Subscriptions & Paywall Plugin for WordPress Developer Profile
1 plugin · 20 total installs
How We Detect Wallkit Subscriptions & Paywall Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wallkit/admin/css/wallkit-wp-admin.min.css/wp-content/plugins/wallkit/public/js/wallkit-wp-public.min.js/wp-content/plugins/wallkit/admin/js/wallkit-wp-admin.min.js/wp-content/plugins/wallkit/admin/js/wallkit-wp-admin.min.js/wp-content/plugins/wallkit/public/js/wallkit-wp-public.min.jswallkit-wp-admin.min.css?ver=wallkit-wp-admin.min.js?ver=wallkit-wp-public.min.js?ver=HTML / DOM Fingerprints
wallkit-admin-wrapwallkit-admin-tabswallkit-inputwallkit-page-settings-wrap<!-- wallkit --><!-- END wallkit --><!-- Wallkit admin -->data-wallkit-fielddata-wallkit-typewindow.wallkit_publiccodemirror_paywall_stylescodemirror_ad/wp-json/wallkit/v1/settings/wp-json/wallkit/v1/content/wp-json/wallkit/v1/users[wallkit_protected_content][wallkit_subscribe_button][wallkit_membership_level]