
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Security & Risk Analysis
wordpress.org/plugins/wc-frontend-manager-direct-paypalDirect pay in vendor's PayPal account from customer account.
Is WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Safe to Use in 2026?
Generally Safe
Score 85/100WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wc-frontend-manager-direct-paypal' v2.0.1 demonstrates a generally good security posture based on the provided static analysis. A key strength is the complete absence of unpatched vulnerabilities and a clean vulnerability history, suggesting a well-maintained and secure development practice. The code also shows robust SQL handling with 100% prepared statements and a high percentage of properly escaped output, significantly mitigating common injection and cross-site scripting risks. The presence of nonce checks for all identified AJAX handlers further reinforces this. However, a notable concern is the complete lack of capability checks on the identified AJAX handlers. While nonces prevent unauthorized requests, they do not restrict actions to authorized users with specific WordPress roles. This could allow any authenticated user to trigger these AJAX actions, potentially leading to unintended consequences or information disclosure if the functionality isn't designed to be public. The single file operation and external HTTP request, while not inherently risky, represent potential attack vectors if not handled with extreme care.
Key Concerns
- AJAX handlers lack capability checks
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Security Vulnerabilities
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Code Analysis
SQL Query Safety
Output Escaping
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Attack Surface
AJAX Handlers 3
WordPress Hooks 21
Maintenance & Trust
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Maintenance & Trust
Maintenance Signals
Community Trust
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Alternatives
WCFM – WCFM Marketplace integrate Elementor
wc-frontend-manager-elementor
Create your marketplace store page using Elementor with your own design. Easily and Beatifully.
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
wc-frontend-manager
Vendor frontend store/shop manager for WC Marketplace, WC Vendors, WC Product Vendors & Dokan with Bookings, Listings & Subscriptions compatib …
WCFM Marketplace – Multivendor Marketplace for WooCommerce
wc-multivendor-marketplace
The most featured and powerful multi vendor plugin for WordPress, setup fantastic woocommerce marketplace store in minutes.
MultiVendorX – WooCommerce Multivendor Marketplace Solutions
dc-woocommerce-multi-vendor
MultiVendorX: WordPress multivendor plugin to build your dream marketplace. Top-rated multi-vendor plugin to launch your dream WooCommerce marketplace …
Split Pay – Stripe Connect Split Payments & Multi-Vendor Marketplace for WooCommerce
bsd-woo-stripe-connect-split-pay
Split payments made in WooCommerce stores between multiple Stripe Connected Accounts and a Stripe Platform Account.
WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace Developer Profile
7 plugins · 52K total installs
How We Detect WCFM – Direct PayPal Pay for WooCommerce Multivendor Marketplace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-frontend-manager-direct-paypal/assets/css/wcfm-paypal-frontend.css/wp-content/plugins/wc-frontend-manager-direct-paypal/assets/js/wcfm-paypal-frontend.js/wp-content/plugins/wc-frontend-manager-direct-paypal/assets/js/wcfm-paypal-checkout.js/wp-content/plugins/wc-frontend-manager-direct-paypal/assets/js/wcfm-paypal-frontend.js/wp-content/plugins/wc-frontend-manager-direct-paypal/assets/js/wcfm-paypal-checkout.jswc-frontend-manager-direct-paypal/assets/css/wcfm-paypal-frontend.css?ver=wc-frontend-manager-direct-paypal/assets/js/wcfm-paypal-frontend.js?ver=wc-frontend-manager-direct-paypal/assets/js/wcfm-paypal-checkout.js?ver=HTML / DOM Fingerprints
wcfm_paypal_marketplace_settingswcfm_paypal_marketplace_connect_buttonwcfm_paypal_marketplace_disconnect_button<!-- WCFMpgdp_TOKEN --><!-- WCFMpgdp_TEXT_DOMAIN --><!-- WCFMpgdp_VERSION --><!-- TODO: add payment fields support in vendor details page & setup wizard -->data-client_iddata-client_secretdata-rest_iddata-merchant_idwcfmpgdp_payfast_gateway_params/wp-json/wcfm-paypal-marketplace/v1/connect/wp-json/wcfm-paypal-marketplace/v1/disconnect