Total Findings
67
Security Grade
Is ifthenpay | Payments for LatePoint secure? In WP HealthKit's independent 2026 audit, ifthenpay | Payments for LatePoint received an overall risk of CRITICAL and a report-card grade of C across 67 findings (1 critical, 7 high severity).
This is a mature, carefully engineered LatePoint payment addon with an unusually strong security posture for a WordPress plugin of its size. The most sensitive surface — the unauthenticated server-to-server callback REST endpoint — implements defense-in-depth: parameter-presence checks first, a token lookup, anti-phishing key verification, an authoritative amount-mismatch check, and row-level locking shared between the callback path and the browser polling path to prevent status-downgrade races. The realtime polling endpoint does not trust the browser's self-reported outcome and instead confirms every txid directly with ifthenpay before settling, and it correctly refuses to mark anything paid when the confirmed order_id does not match the local token. The admin surfaces are equally disciplined: the tools page double-checks a LatePoint capability (settings__edit) in addition to add_options_page's manage_options gate, nonces protect every mutating POST action, and all rendered output (tokens, customer names, emails, amounts, URLs) is consistently escaped with context-appropriate functions. Customer-facing checkout endpoints avoid sequential-ID enumeration by resolving invoices via LatePoint's opaque access_key, and fresh random tokens (wp_generate_password(20)) are minted per checkout attempt, avoiding token-reuse double charges. The remaining issues are low-severity: the anti-phishing gateway key is stored in plaintext (settings and per-transaction rows) while the backoffice key is encrypted; the polling endpoint's generic exception handler echoes raw exception messages to unauthenticated browsers; and several ifthenpay API contracts force credentials into GET query strings (a protocol constraint, partially unavoidable). No SQL injection, XSS, CSRF, authentication bypass, or amount-tampering vulnerability was confirmed in the code provided. Note that several key classes referenced by this code (transaction repository, settlement, callback params, data formatter) were not included in the audit set, so findings about those internals are stated as assumptions rather than confirmed facts.
Show your audit status in your README or website.
[](https://wphealthkit.com/directory/ifthenpay-payments-for-latepoint)
Paste this in your GitHub README or any Markdown file. The badge updates automatically on every re-audit — no need to refresh the snippet.
Site owners: should they update? See the update-safety verdict for ifthenpay | Payments for LatePoint
Claim this listing to get a Verified badge, control public audits, and get automatic re-scans.
Claim This PluginGet a comprehensive security audit for your WordPress plugin or theme. Upload your zip and get results in minutes.
Start Free AuditProduction Ready
Needs WorkWP.org Ready
Needs ChangesCompliance
Non-Compliant