shouldiuse.io

Categories

VERDICT

Should I use Supsystic?

WordPress Plugins by Supsystic - supsystic.com

Skip. Easy-to-use WordPress plugins with a free tier, but a 68-CVE history — including RCE and a Pro backdoor — makes them a security liability. Tinkerers can experiment; anyone running a business site should look elsewhere.

Confidence

Medium. Based on 30+ public sources: WordPress.org forums, CVE databases (NVD, WPScan, SentinelOne, SecAlerts), Trustpilot, and BuiltWith.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Personal blogs and hobby sites
  • Quick one-off pricing tables or galleries
  • Non-technical WordPress users wanting drag-and-drop

Not for

  • Business sites handling customer data
  • Anyone needing responsive paid support
  • Agencies maintaining many client sites
  • Ecommerce or membership sites

Gotchas - check before you buy

high

Auth bypass vulnerabilities found in Ultimate Maps and Popup plugins; outdated installs are exposed.

high

Vulnerability pattern repeats yearly: 2020 Wordfence report, 2023 CVEs, 2026 RCE.

high

Pro users report support tickets going unanswered.

medium

Free versions push paid upgrades; users describe bait-and-switch behavior.

Pros and cons

Pros

  • Broad free plugin suite: galleries, tables, popups, maps, forms, sliders
  • Users report 12 years of experience with Data Tables Generator
  • Pricing Table plugin rated 4.1/5 across 10K+ installs
  • Third-party architectural review says it 'stands out' among gallery plugins

Cons

  • 68 known CVEs across the plugin line
  • Remote code execution flaw in Contact Form plugin (CVE-2026-4257)
  • Backdoor reported in multiple Pro plugins
  • Users allege bait-and-switch between free and paid versions
  • Paying users report 'no support at all'

Sources & method

Analyzed 10/07/2026 - 14 sources - Poor: vendor tracker lists 68 CVEs including RCE, auth bypasses, SQLi, and a backdoor in Pro plugins.

official x2review x7security x4news x1
  • Contact Form RCE (CVE-2026-4257), Remote code execution vulnerability in Contact Form by Supsystic plugin.
  • Backdoor in multiple Pro plugins, WPScan reports a backdoor delivered via multiple Supsystic Pro plugins.
  • Ultimate Maps auth bypass (CVE-2026-73377), Authentication bypass flaw in Ultimate Maps plugin, disclosed August 2026.
  • Popup XSS (CVE-2026-102398), Cross-site scripting in Popup by Supsystic, CVSS 7.1.

Key stats

  • Value for money: 2/5

    Rating

  • Not disclosed

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 2/5. Bait-and-switch upsell complaints from users
  • Ease of use: 4/5. Reviewers call plugins easy and efficient
  • Feature depth: 3/5. Wide suite: tables, galleries, popups, maps, forms
  • Support quality: 1/5. Repeated 'NO SUPPORT' threads from paying users
  • Security posture: 1/5. 68 CVEs, RCE, backdoor in Pro plugins
  • 4.1/5 Pricing Table rating 10K+ installs (PageForge)
  • 68 Known CVEs SecAlerts vendor tracking
  • 1,986 Live sites using Pricing Table BuiltWith
  • 100,000+ Vendor-claimed users per supsystic.com

Pricing

Free tier: Yes

Security

Poor: vendor tracker lists 68 CVEs including RCE, auth bypasses, SQLi, and a backdoor in Pro plugins.

  • Contact Form RCE (CVE-2026-4257)Remote code execution vulnerability in Contact Form by Supsystic plugin.⁸
  • Backdoor in multiple Pro pluginsWPScan reports a backdoor delivered via multiple Supsystic Pro plugins.⁹
  • Ultimate Maps auth bypass (CVE-2026-73377)Authentication bypass flaw in Ultimate Maps plugin, disclosed August 2026.
  • Popup XSS (CVE-2026-102398)Cross-site scripting in Popup by Supsystic, CVSS 7.1.

Companies that use it

  • New York City Council
  • Extension Architecture
Full analysis

Based on 30+ public sources: WordPress.org forums, CVE databases (NVD, WPScan, SentinelOne, SecAlerts), Trustpilot, and BuiltWith.

Powerful free WP plugins, but 68 CVEs, an RCE, and a Pro backdoor plus weak support make it a hard no for business sites.

Methodology

Based on 30+ public sources: WordPress.org forums, CVE databases (NVD, WPScan, SentinelOne, SecAlerts), Trustpilot, and BuiltWith.

Sources

  1. review
  2. review
  3. review
  4. review
  5. review
  6. news
  7. security
  8. security
  9. security
  10. security
  11. Supsystic homepagesupsystic.com
    official
  12. official
  13. review
  14. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.