Aircash for WooCommerce Security & Risk Analysis

wordpress.org/plugins/aircash-for-woocommerce

We make payments even faster, safer and easier – 24/7! Simple to use and extra safe for you and your customers.

100 active installs v2.0.7 PHP 7.1+ WP 4.7+ Updated Mar 3, 2026
onlinepaypaymentscanwebshop
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Aircash for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Aircash for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The aircash-for-woocommerce plugin v2.0.7 demonstrates several positive security practices, including 100% use of prepared statements for SQL queries and a lack of recorded vulnerabilities (CVEs). However, there are notable concerns regarding its attack surface. Specifically, the plugin exposes two AJAX handlers without authentication checks, presenting a significant risk. While taint analysis and SQL query methods are clean, the insufficient authorization on AJAX endpoints could allow unauthorized actions if these handlers are exploitable. The plugin also has a moderate number of file operations and external HTTP requests, which, while not inherently risky, warrant careful review in conjunction with the unprotected entry points.

Despite the absence of historical vulnerabilities, the presence of unprotected AJAX handlers suggests a potential for future security weaknesses if not addressed. The plugin's reliance on jQuery is standard, but the overall security posture is weakened by the exposed AJAX endpoints. In conclusion, while the plugin benefits from good SQL handling and a clean vulnerability history, the unprotected AJAX handlers represent a critical area of concern that requires immediate attention to mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
  • Moderate number of file operations
  • Moderate number of external HTTP requests
  • Only 1 capability check for 3 entry points
Vulnerabilities
None known

Aircash for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Aircash for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
60
101 escaped
Nonce Checks
2
Capability Checks
1
File Operations
4
External Requests
8
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

63% escaped161 total outputs
Attack Surface
2 unprotected

Aircash for WooCommerce Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

noprivwp_ajax_aircash_order_checkaircash-woocommerce.php:43
authwp_ajax_aircash_order_checkaircash-woocommerce.php:44
authwp_ajax_aircash_dismiss_noticeaircash-woocommerce.php:65
WordPress Hooks 23
actioninitaircash-woocommerce.php:20
filterwoocommerce_payment_gatewaysaircash-woocommerce.php:40
filterkses_allowed_protocolsaircash-woocommerce.php:42
actionadmin_initaircash-woocommerce.php:45
actioninitaircash-woocommerce.php:46
actionaircash_order_cron_hookaircash-woocommerce.php:47
filtercron_schedulesaircash-woocommerce.php:51
actionadmin_initaircash-woocommerce.php:57
actionadmin_initaircash-woocommerce.php:58
actionin_admin_footeraircash-woocommerce.php:59
actionadmin_noticesaircash-woocommerce.php:64
actionplugins_loadedaircash-woocommerce.php:336
actionwoocommerce_api_aircashincludes\class-aircash-payment-gateway.php:71
actionwoocommerce_api_aircash_successincludes\class-aircash-payment-gateway.php:75
actionwoocommerce_api_aircash_declineincludes\class-aircash-payment-gateway.php:76
actionwoocommerce_api_aircash_cancelincludes\class-aircash-payment-gateway.php:77
filterwp_enqueue_scriptsincludes\class-aircash-payment-gateway.php:79
actionaircash_cron_hookincludes\class-aircash-payment-gateway.php:80
actionadmin_headincludes\class-aircash-payment-gateway.php:81
actionadd_meta_boxesincludes\class-aircash-payment-gateway.php:82
actionsave_postincludes\class-aircash-payment-gateway.php:83
actionadmin_footerincludes\class-aircash-payment-gateway.php:84
actionadmin_enqueue_scriptsincludes\class-aircash-payment-gateway.php:238

Scheduled Events 1

aircash_order_cron_hook
Maintenance & Trust

Aircash for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 3, 2026
PHP min version7.1
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Aircash for WooCommerce Developer Profile

Aircash

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aircash for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aircash-for-woocommerce/assets/css/aircash.css/wp-content/plugins/aircash-for-woocommerce/assets/js/aircash.js/wp-content/plugins/aircash-for-woocommerce/assets/js/aircash-payment-gateway.js/wp-content/plugins/aircash-for-woocommerce/assets/js/aircash-checkout.js
Script Paths
/wp-content/plugins/aircash-for-woocommerce/assets/js/aircash.js/wp-content/plugins/aircash-for-woocommerce/assets/js/aircash-payment-gateway.js/wp-content/plugins/aircash-for-woocommerce/assets/js/aircash-checkout.js
Version Parameters
aircash-for-woocommerce/assets/css/aircash.css?ver=aircash-for-woocommerce/assets/js/aircash.js?ver=aircash-for-woocommerce/assets/js/aircash-payment-gateway.js?ver=aircash-for-woocommerce/assets/js/aircash-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
aircash-payment-formaircash-checkout-sectionaircash-noticeaircash-test-mode-noticeaircash-account-request-noticeaircash-settings-fields
HTML Comments
<!-- Aircash for WooCommerce Payment Gateway --><!-- Aircash Payment Form --><!-- Aircash Checkout Section --><!-- Aircash Admin Notices -->
Data Attributes
data-aircash-payment-urldata-aircash-order-id
JS Globals
aircash_paramsaircash_checkout_params
REST Endpoints
/wp-json/aircash/v1/order-check
Shortcode Output
[aircash_payment_button][aircash_checkout_form]
FAQ

Frequently Asked Questions about Aircash for WooCommerce