
2Checkout Integration for WordPress – WP Super Pay Security & Risk Analysis
wordpress.org/plugins/2checkout2Checkout integration for WordPress. Collect donation and payments without any E-commerce programs
Is 2Checkout Integration for WordPress – WP Super Pay Safe to Use in 2026?
Generally Safe
Score 85/1002Checkout Integration for WordPress – WP Super Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 2Checkout plugin v1.0 exhibits a mixed security posture. While it boasts a seemingly small attack surface with no unprotected entry points like AJAX handlers, REST API routes, or shortcodes, and no publicly disclosed vulnerabilities (CVEs), significant concerns arise from the static code analysis. The presence of the dangerous `unserialize` function, coupled with two taint flows identified with unsanitized paths, indicates a high risk of deserialization vulnerabilities. These can lead to remote code execution if an attacker can control the data being unserialized. Furthermore, the absence of nonce checks and capability checks is alarming, as these are fundamental WordPress security mechanisms to prevent Cross-Site Request Forgery (CSRF) and unauthorized actions. The fact that 60% of SQL queries are not using prepared statements also presents a risk of SQL injection. Despite the lack of historical CVEs, the internal code signals suggest a plugin that requires immediate attention to address these inherent security weaknesses before they can be exploited.
Key Concerns
- Dangerous function: unserialize
- Taint flows with unsanitized paths (high severity)
- SQL queries not using prepared statements
- No nonce checks
- No capability checks
- Low output escaping percentage
2Checkout Integration for WordPress – WP Super Pay Security Vulnerabilities
2Checkout Integration for WordPress – WP Super Pay Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
2Checkout Integration for WordPress – WP Super Pay Attack Surface
Scheduled Events 1
Maintenance & Trust
2Checkout Integration for WordPress – WP Super Pay Maintenance & Trust
Maintenance Signals
Community Trust
2Checkout Integration for WordPress – WP Super Pay Alternatives
Payment Gateway – 2Checkout for WooCommerce
woo-2checkout
2Checkout Payment Gateway for WooCommerce allow to accept online store payment from Paypal, Credit Card, MasterCard and more.
Donate by BestWebSoft – Donations Acception Extention for WordPress
donate-button
Add PayPal and 2CO donate buttons to receive charity payments.
2CPay
2cpay
2CPay is a 2Checkout plugin developed for Woocommerce
Accept 2Checkout Payments Using Contact Form 7
accept-2checkout-payments-using-contact-form-7
The 2Checkout Payment system provides a secure, simple means of authorizing credit and debit card transactions from your website.
Contact Form 7 2Checkout
cf7-2checkout
Twochout payment gateway integrated with contact form 7
2Checkout Integration for WordPress – WP Super Pay Developer Profile
10 plugins · 41K total installs
How We Detect 2Checkout Integration for WordPress – WP Super Pay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/2checkout/assets/css/admin.css/wp-content/plugins/2checkout/assets/js/admin.js/wp-content/plugins/2checkout/assets/css/style.css/wp-content/plugins/2checkout/assets/js/scripts.js/wp-content/plugins/2checkout/assets/js/admin.js/wp-content/plugins/2checkout/assets/js/scripts.js2checkout/assets/css/admin.css?ver=2checkout/assets/js/admin.js?ver=2checkout/assets/css/style.css?ver=2checkout/assets/js/scripts.js?ver=HTML / DOM Fingerprints
wp-2checkout-shortcodetwocheckout-payment-formcodexpert-pluginif accessed directly, exit.Admin facing hooksFront facing hooksShortcode hooksdata-2checkout-iddata-amountdata-currencydata-product-nametwoCheckout[2checkout