
Akouendy Mobile Money Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/akouendy-woocommerce-orange-money-gatewayThe plugins is Senegal Mobile Money gateway for Woocommerce.
Is Akouendy Mobile Money Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Akouendy Mobile Money Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "akouendy-woocommerce-orange-money-gateway" v4.0.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities (CVEs) and no recorded critical or high-severity issues in its history are strong indicators of responsible development. The code analysis reveals a clean record for dangerous functions and SQL queries, with all SQL operations utilizing prepared statements, which is an excellent practice to prevent SQL injection. The plugin also has a moderate number of file operations and external HTTP requests, which are common for payment gateways and require careful handling, but no specific risks were flagged in this regard.
However, there are areas for improvement. The most significant concern is the complete lack of nonce and capability checks across all identified entry points. This means that if any entry points were present but not explicitly listed (e.g., hidden AJAX calls or REST API endpoints not caught by the analysis), they would be vulnerable to CSRF attacks and unauthorized privilege escalation. Furthermore, with 56% of output escaping being properly done, there's still a 44% chance of improper output escaping, which could lead to Cross-Site Scripting (XSS) vulnerabilities if sensitive data is displayed without proper sanitization. While the current analysis shows no unsanitized taint flows, the absence of comprehensive checks on entry points leaves room for potential issues.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the lack of fundamental security checks like nonces and capability checks is a critical weakness. The moderate rate of properly escaped output also presents a potential XSS risk. Developers should prioritize implementing these essential security measures to harden the plugin against common web attacks, even if the current analysis doesn't reveal any immediate, exploitable vulnerabilities.
Key Concerns
- No nonce checks found
- No capability checks found
- 44% of outputs not properly escaped
Akouendy Mobile Money Gateway for WooCommerce Security Vulnerabilities
Akouendy Mobile Money Gateway for WooCommerce Code Analysis
Output Escaping
Akouendy Mobile Money Gateway for WooCommerce Attack Surface
WordPress Hooks 12
Maintenance & Trust
Akouendy Mobile Money Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Akouendy Mobile Money Gateway for WooCommerce Alternatives
UnitechPay – Wave & Orange Money Payments
unitechpay-paiements-mobile-money
Solution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !
Paiement Wave Senegal
paiement-wave-senegal
Une extension WooCommerce pour accepter les paiements via Wave Mobile Money au Sénégal.
HelloAsso
helloasso
HelloAsso est la solution gratuite des associations pour collecter des paiements et des dons sur internet.
Flutterwave WooCommerce
rave-woocommerce-payment-gateway
The WooCommerce Plugin makes it very easy and quick to add Flutterwave Payment option on Checkout for your online store. Accept Credit card, Debit car …
Flutterwave Payment Gateway for WooCommerce
woo-rave
Flutterwave payment gateway for WooCommerce plugin allows you to accept payment on your WooCommerce store through multiple payment channels via Flutte …
Akouendy Mobile Money Gateway for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Akouendy Mobile Money Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/akouendy-woocommerce-orange-money-gateway/assets/css/akouendy-style.css/wp-content/plugins/akouendy-woocommerce-orange-money-gateway/assets/js/akouendy-pay-widget-v1.0.0.jsakouendy-woocommerce-orange-money-gateway/assets/js/akouendy-pay-widget-v1.0.0.js?ver=akouendy-woocommerce-orange-money-gateway/assets/css/akouendy-style.css?ver=HTML / DOM Fingerprints
akd-orange-money-sndata-provider="orange-money-sn-api"WC_OM_SN_Gateway_Blocks_SupportWC_WAVE_SN_Gateway_Blocks_Support/v1/billing/payment/init/v1/payment/{paymenId}/{applicationId}/v1/billing/{provider}/{token}/v1/billing/{provider}/{token}