Title: Standard Key API security issue
Last modified: July 10, 2023

---

# Standard Key API security issue

 *  Resolved [efox](https://wordpress.org/support/users/foxylearning/)
 * (@foxylearning)
 * [2 years, 11 months ago](https://wordpress.org/support/topic/standard-key-api-security-issue/)
 * Is this plugin susceptible to the security risks associated with using Stripe’s
   standard API keys (rather than a restricted API key)? If so, are there plans 
   to address this issue?
 * For more information, the issue is being discussed for the default Stripe plugin
   offered by WooCommerce [here on GitHub](https://github.com/woocommerce/woocommerce-gateway-stripe/issues/634).
   The security risk associated with using the standard API keys is illustrated 
   in [this blog post](https://webdesigneracademy.com/my-stripe-account-was-hacked-and-stripe-said-i-have-to-repay-70k/),
   where the business owner has been told by Stripe that she is responsible for 
   $70,000 in fraudulent charges made as a result of this security vulnerability.

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Author [Clayton R](https://wordpress.org/support/users/mrclayton/)
 * (@mrclayton)
 * [2 years, 11 months ago](https://wordpress.org/support/topic/standard-key-api-security-issue/#post-16883930)
 * Hi [@foxylearning](https://wordpress.org/support/users/foxylearning/)
 * [Here is our response](https://wordpress.org/support/topic/supporting-restricted-api-keys/)
   to a similar request from several weeks ago. In short, our plugin is not susceptible
   to that exploit.
 * Kind Regards
 *  Thread Starter [efox](https://wordpress.org/support/users/foxylearning/)
 * (@foxylearning)
 * [2 years, 11 months ago](https://wordpress.org/support/topic/standard-key-api-security-issue/#post-16884355)
 * Thanks. I apologize for missing that other post. This can be closed as it is 
   a duplicate.

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Standard Key API security issue’ is closed to new replies.

 * ![](https://ps.w.org/woo-stripe-payment/assets/icon-256x256.png?rev=2611337)
 * [Payment Plugins for Stripe WooCommerce](https://wordpress.org/plugins/woo-stripe-payment/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woo-stripe-payment/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woo-stripe-payment/)
 * [Active Topics](https://wordpress.org/support/plugin/woo-stripe-payment/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woo-stripe-payment/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woo-stripe-payment/reviews/)

 * 2 replies
 * 2 participants
 * Last reply from: [efox](https://wordpress.org/support/users/foxylearning/)
 * Last activity: [2 years, 11 months ago](https://wordpress.org/support/topic/standard-key-api-security-issue/#post-16884355)
 * Status: resolved