
Zoho Billing – Embed Payment Form Security & Risk Analysis
wordpress.org/plugins/zoho-subscriptionsEmbed payment forms on your WordPress pages/posts without any coding.
Is Zoho Billing – Embed Payment Form Safe to Use in 2026?
Mostly Safe
Score 77/100Zoho Billing – Embed Payment Form is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The zoho-subscriptions plugin version 4.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a low number of entry points with zero identified as unprotected. The static analysis also shows a good rate of output escaping and the presence of a nonce check. However, the complete absence of capability checks is a significant concern, suggesting that access control might be improperly implemented, potentially leaving features vulnerable to unauthorized use. Additionally, the plugin has a history of two known CVEs, one of which remains unpatched. Both historical vulnerabilities were classified as medium severity and related to Cross-site Scripting, indicating a recurring pattern of input sanitization issues.
Key Concerns
- Unpatched CVE
- No capability checks
- Medium severity vulnerabilities in history
- Low percentage of properly escaped output
Zoho Billing – Embed Payment Form Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Zoho Billing <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Zoho Billing – Embed Payment Form <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Zoho Billing – Embed Payment Form Code Analysis
Output Escaping
Zoho Billing – Embed Payment Form Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Zoho Billing – Embed Payment Form Maintenance & Trust
Maintenance Signals
Community Trust
Zoho Billing – Embed Payment Form Alternatives
Pay with Vipps and MobilePay for WooCommerce
woo-vipps
Official Vipps MobilePay payment plugin for WooCommerce.
Memberful – Membership Plugin
memberful-wp
Sell memberships and restrict access to content with WordPress and Memberful.
Fygaro WC Plugin
fygaro
The WooCommerce Fygaro Plugin gets online payments with your Local Bank, PayPal, Yappy and Credix up and running within minutes and at the best rates!
Recurio – Ultimate Subscription Plugin for WooCommerce
recurio
A powerful and comprehensive WooCommerce subscription management plugin with advanced analytics, automated billing, and customer portal.
Bykea.Cash – Online Payments
bykea-cash-online-payments
The Bykea Cash plugin allows you to collect payments on your WordPress WooCommerce website instantly using Credit/Debit Cards (VISA, MasterCard, PayPa …
Zoho Billing – Embed Payment Form Developer Profile
1 plugin · 500 total installs
How We Detect Zoho Billing – Embed Payment Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zoho-subscriptions/assets/css/zoho-subscriptions.cssHTML / DOM Fingerprints
zswelcomepanouterzswelcomepanzswelheadingzslinkzssmallinkdata-plugin-name="zoho-subscriptions"data-plugin-version="4.1"showErrorMessagezs_api_key