2C2P Redirect API for WooCommerce Security & Risk Analysis

wordpress.org/plugins/2c2p-redirect-api-for-woocommerce

Accept Payment (Credit/Debit Cards, Alipay, Alternative/Cash Payments) on your WooCommerce webstore.

900 active installs v7.0.3 PHP + WP 2.6.0+ Updated Jun 4, 2018
2c2pe-commerceecommercewoocommercewordpress-ecommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is 2C2P Redirect API for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

2C2P Redirect API for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The security posture of the "2c2p-redirect-api-for-woocommerce" v7.0.3 plugin presents significant concerns primarily due to its unprotected entry points. While the plugin demonstrates good practices in its handling of SQL queries and output escaping, the absence of authentication checks on its AJAX handlers creates a direct pathway for attackers to potentially exploit these functions. This lack of authorization is a critical oversight that can lead to unauthorized actions or information disclosure. The static analysis reveals two AJAX handlers, both of which lack authentication, contributing to a total of two unprotected entry points, which represents a substantial attack surface. The absence of known vulnerabilities in its history is a positive sign, suggesting that the core functionality might be relatively secure or that it hasn't been a target. However, this does not mitigate the immediate risks identified in the code analysis. The plugin's strengths lie in its secure database interactions and proper output sanitization, but these are overshadowed by the critical flaw of unprotected AJAX endpoints. A balanced conclusion is that while the plugin avoids common pitfalls like raw SQL or unescaped output, the fundamental security lapse of exposed AJAX handlers demands immediate attention and remediation.

Key Concerns

  • AJAX handlers without authentication checks
  • Unprotected AJAX handlers contribute to attack surface
Vulnerabilities
None known

2C2P Redirect API for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

2C2P Redirect API for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
59 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped69 total outputs
Attack Surface
2 unprotected

2C2P Redirect API for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_paymentajax2c2p.php:589
noprivwp_ajax_paymentajax2c2p.php:590
WordPress Hooks 11
actionplugins_loaded2c2p.php:10
actionadmin_head2c2p.php:11
actioninit2c2p.php:12
filterwc_order_statuses2c2p.php:13
actioninit2c2p.php:178
actionwoocommerce_receipt_2c2p2c2p.php:180
actionwoocommerce_checkout_update_order_meta2c2p.php:181
actionwp_enqueue_scripts2c2p.php:184
actionwoocommerce_update_options_payment_gateways2c2p.php:190
filterwoocommerce_payment_gateways2c2p.php:627
filterplugin_action_links2c2p.php:632
Maintenance & Trust

2C2P Redirect API for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 4, 2018
PHP min version
Downloads8K

Community Trust

Rating40/100
Number of ratings1
Active installs900
Developer Profile

2C2P Redirect API for WooCommerce Developer Profile

2c2p

1 plugin · 900 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 2C2P Redirect API for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/2c2p-redirect-api-for-woocommerce/assets/js/main.js/wp-content/plugins/2c2p-redirect-api-for-woocommerce/assets/css/main.css
Script Paths
/wp-content/plugins/2c2p-redirect-api-for-woocommerce/assets/js/main.js
Version Parameters
2c2p-redirect-api-for-woocommerce/assets/js/main.js?ver=2c2p-redirect-api-for-woocommerce/assets/css/main.css?ver=

HTML / DOM Fingerprints

CSS Classes
awaiting-payment
JS Globals
wc_2c2p_params
REST Endpoints
/wp-json/2c2p-gateway/v1
FAQ

Frequently Asked Questions about 2C2P Redirect API for WooCommerce