
WPFormify – Stripe Payments with Form and Checkout Security & Risk Analysis
wordpress.org/plugins/wpformifyIn a few simple steps you can start accepting credit card payments with Stripe Checkout on your WordPress site.
Is WPFormify – Stripe Payments with Form and Checkout Safe to Use in 2026?
Generally Safe
Score 100/100WPFormify – Stripe Payments with Form and Checkout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpformify" v1.1.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices with SQL queries being exclusively prepared and a complete lack of recorded historical vulnerabilities, suggesting a generally well-maintained codebase. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a seemingly controlled environment.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without any authentication checks, creating a substantial attack surface for unauthorized actions. While taint analysis shows no critical or high-severity unsanitized flows, the presence of five flows with unsanitized paths warrants caution, even if they didn't reach a critical severity in this analysis. A concerning 87% of output is not properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is echoed directly to the browser. The inclusion of the Freemius v1.0 bundled library could also pose a risk if it's outdated or has known vulnerabilities not specifically tied to this plugin's direct code.
The lack of vulnerability history is a strength, but it shouldn't overshadow the immediate risks identified in the code analysis. The plugin needs to prioritize implementing proper authentication and capability checks on its AJAX endpoints and address the widespread output escaping issues to mitigate the immediate security threats.
Key Concerns
- 2 AJAX handlers without auth checks
- 13% output properly escaped (87% unescaped)
- 5 flows with unsanitized paths (taint analysis)
- Bundled Freemius v1.0 library
WPFormify – Stripe Payments with Form and Checkout Security Vulnerabilities
WPFormify – Stripe Payments with Form and Checkout Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WPFormify – Stripe Payments with Form and Checkout Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
WPFormify – Stripe Payments with Form and Checkout Maintenance & Trust
Maintenance Signals
Community Trust
WPFormify – Stripe Payments with Form and Checkout Alternatives
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
Stripe Payment Forms by WP Simple Pay – Accept Credit Card Payments + Subscriptions with Stripe
stripe
🤩 Accept Stripe payments and recurring subscriptions on your WordPress using WP Simple Pay, the best Stripe payments plugin! 🚀
Accept Stripe Payments
stripe-payments
Easily accept payments on your WordPress site via Stripe payment gateway.
Payment Gateway of Stripe for WooCommerce
payment-gateway-stripe-and-woocommerce-integration
Integrate Stripe Payment Gateway in WooCommerce and accept cards, Google Pay, Apple Pay, Klarna, Alipay, and more with seamless, secure checkout.
GetPaid Stripe Payments
getpaid-stripe-payments
Stripe Payments for WordPress made easy. Accept credit cards on your WordPress site using the Stripe payments add-on for GetPaid.
WPFormify – Stripe Payments with Form and Checkout Developer Profile
84 plugins · 1.4M total installs
How We Detect WPFormify – Stripe Payments with Form and Checkout
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpformify/assets/backend/css/wpf_backend_styles.css/wp-content/plugins/wpformify/assets/backend/js/wpf_backend_scripts_free.js/wp-content/plugins/wpformify/assets/backend/js/jscolor.jshttps://js.stripe.com/v3/wpformify/assets/backend/css/wpf_backend_styles.css?ver=wpformify/assets/backend/js/wpf_backend_scripts_free.js?ver=wpformify/assets/backend/js/jscolor.js?ver=HTML / DOM Fingerprints
wpformiFy-formwpformiFyblocktitleswtichWrapswitch-inputswitch-labeltoggle--ontoggle--option+9 moredata-mode="live"data-mode="test"