
WP Express Checkout (Fast Payments via PayPal & Stripe) Security & Risk Analysis
wordpress.org/plugins/wp-express-checkoutAllows you to accept fast and secure payments for products and services via a payment popup window, supporting both the new PayPal and Stripe Checkout …
Is WP Express Checkout (Fast Payments via PayPal & Stripe) Safe to Use in 2026?
Generally Safe
Score 99/100WP Express Checkout (Fast Payments via PayPal & Stripe) has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-express-checkout v2.4.6 plugin exhibits a generally good security posture with several strong practices, including the exclusive use of prepared statements for SQL queries and a high rate of output escaping (82%). The absence of critical or high-severity known vulnerabilities and the fact that all past CVEs are patched are positive indicators. However, the plugin has a notable attack surface with 30 AJAX handlers, 5 of which lack authentication checks. While the taint analysis did not reveal any critical or high-severity unsanitized flows, the presence of 3 flows with unsanitized paths, even if assessed as low or medium severity by the analysis tool, warrants attention. The history of 2 medium-severity CVEs, with the most recent in March 2024, indicates that while vulnerabilities are being addressed, there's a pattern of issues that could be exploited if left unpatched. The combination of unprotected AJAX endpoints and a history of vulnerabilities suggests a moderate risk level. Further investigation into the nature of the 3 unsanitized flows and the historical CVEs is recommended.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- History of medium severity CVEs
WP Express Checkout (Fast Payments via PayPal & Stripe) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Express Checkout (Accept PayPal Payments) <= 2.3.7 - Unauthenticated Price Manipulation
WP Express Checkout <= 2.2.8 - Authenticated (Admin+) Stored Cross-Site Scripting via pec_coupon[code]
WP Express Checkout (Fast Payments via PayPal & Stripe) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Express Checkout (Fast Payments via PayPal & Stripe) Attack Surface
AJAX Handlers 30
Shortcodes 6
WordPress Hooks 63
Maintenance & Trust
WP Express Checkout (Fast Payments via PayPal & Stripe) Maintenance & Trust
Maintenance Signals
Community Trust
WP Express Checkout (Fast Payments via PayPal & Stripe) Alternatives
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
easy-digital-downloads
The #1 eCommerce plugin to sell digital products & subscriptions. Accept credit card payments with Stripe & PayPal and start your store today.
Contact Form 7 – PayPal & Stripe Add-on
contact-form-7-paypal-add-on
Easily add PayPal and Stripe to Contact Form 7. Accept credit card payments with Stripe & PayPal on your site today. Offical PayPal & Stripe Partner.
Simple Payment Module for Divi
wpz-payments-free
A payment module for Divi that supports both Stripe and PayPal!
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
WP Express Checkout (Fast Payments via PayPal & Stripe) Developer Profile
15 plugins · 210K total installs
How We Detect WP Express Checkout (Fast Payments via PayPal & Stripe)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-express-checkout/assets/css/admin.css/wp-content/plugins/wp-express-checkout/assets/js/admin.js/wp-content/plugins/wp-express-checkout/assets/js/admin.jswp-express-checkout/assets/css/admin.css?ver=wp-express-checkout/assets/js/admin.js?ver=HTML / DOM Fingerprints
wpec-products-adminwpec-orders-adminwpec-ppec-productswpec-paypal-express-checkout-buttonwpec-stripe-checkout-button<!-- WPEC Admin User Feedback --><!-- WPEC Admin Notice --><!-- WPEC Product Form --><!-- WPEC Product Details -->+2 moredata-wpec-product-iddata-wpec-currencydata-wpec-amountdata-wpec-button-textdata-wpec-payment-methoddata-wpec-stripe-publishable-keywindow.wpec_ajax_object/wp-json/wpec/v1/create-payment-intent/wp-json/wpec/v1/process-payment/wp-json/wpec/v1/validate-coupon[wp_express_checkout][wpec_product_details][wpec_payment_form]