AffiniPay WooCommerce Security & Risk Analysis

wordpress.org/plugins/affinipay-woocommerce

Take credit card payments on your WooCommerce site using AffiniPay

60 active installs v1.5.2 PHP 5.3+ WP 4.4.0+ Updated Apr 16, 2024
affinipaypaymentswoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AffiniPay WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

AffiniPay WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The affiniPay-WooCommerce plugin version 1.5.2 presents a generally positive security posture based on the provided static analysis. The plugin demonstrates strong adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements exclusively for SQL queries, and incorporating nonce checks and capability checks. Notably, there are no recorded CVEs, indicating a clean vulnerability history and a proactive approach to security by the developers. The absence of taint analysis findings further suggests that there are no immediately obvious critical or high severity vulnerabilities related to data sanitization or insecure flows.

However, a significant concern arises from the output escaping. With 43% of outputs properly escaped, this leaves a substantial portion (57%) potentially vulnerable to cross-site scripting (XSS) attacks. While the attack surface appears minimal with no reported AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication, the unescaped output remains a potential vector for attackers to inject malicious scripts, especially if user-supplied data is ever displayed without proper sanitization.

In conclusion, the plugin has a strong foundation with no critical vulnerabilities found and a clean history. The primary area requiring immediate attention is the output escaping, which needs to be addressed to mitigate potential XSS risks. Addressing this would significantly improve the plugin's overall security.

Key Concerns

  • Significant portion of output unescaped
Vulnerabilities
None known

AffiniPay WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AffiniPay WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
12 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

43% escaped28 total outputs
Attack Surface

AffiniPay WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterwoocommerce_payment_gatewayschargeio-for-woocommerce.php:49
actionwoocommerce_order_status_processing_to_completedchargeio-for-woocommerce.php:50
actionwoocommerce_after_my_accountclasses\class-cio4wc_customer.php:17
actionshow_user_profileclasses\class-cio4wc_customer.php:18
actionedit_user_profileclasses\class-cio4wc_customer.php:19
actionadmin_noticesclasses\class-cio4wc_customer.php:20
actionwoocommerce_update_options_payment_gatewaysclasses\class-cio4wc_gateway.php:61
actionadmin_noticesclasses\class-cio4wc_gateway.php:63
actionwp_enqueue_scriptsclasses\class-cio4wc_gateway.php:64
actionwoocommerce_credit_card_form_startclasses\class-cio4wc_gateway.php:65
Maintenance & Trust

AffiniPay WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 16, 2024
PHP min version5.3
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

AffiniPay WooCommerce Developer Profile

affinipayudev

2 plugins · 110 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AffiniPay WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affinipay-woocommerce/classes/class-cio4wc-api.php/wp-content/plugins/affinipay-woocommerce/classes/class-cio4wc-db.php/wp-content/plugins/affinipay-woocommerce/classes/class-cio4wc-customer.php/wp-content/plugins/affinipay-woocommerce/classes/class-cio4wc-gateway.php/wp-content/plugins/affinipay-woocommerce/classes/class-cio4wc-subscriptions-gateway.php/wp-content/plugins/affinipay-woocommerce/templates/

HTML / DOM Fingerprints

HTML Comments
<!-- Manual capture is not supported at this time -->
FAQ

Frequently Asked Questions about AffiniPay WooCommerce