Akouendy Mobile Money Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/akouendy-woocommerce-orange-money-gateway

The plugins is Senegal Mobile Money gateway for Woocommerce.

10 active installs v4.0.1 PHP 7.0+ WP 5.7+ Updated Sep 23, 2025
orange-moneypaiementsenegalwave
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Akouendy Mobile Money Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Akouendy Mobile Money Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "akouendy-woocommerce-orange-money-gateway" v4.0.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities (CVEs) and no recorded critical or high-severity issues in its history are strong indicators of responsible development. The code analysis reveals a clean record for dangerous functions and SQL queries, with all SQL operations utilizing prepared statements, which is an excellent practice to prevent SQL injection. The plugin also has a moderate number of file operations and external HTTP requests, which are common for payment gateways and require careful handling, but no specific risks were flagged in this regard.

However, there are areas for improvement. The most significant concern is the complete lack of nonce and capability checks across all identified entry points. This means that if any entry points were present but not explicitly listed (e.g., hidden AJAX calls or REST API endpoints not caught by the analysis), they would be vulnerable to CSRF attacks and unauthorized privilege escalation. Furthermore, with 56% of output escaping being properly done, there's still a 44% chance of improper output escaping, which could lead to Cross-Site Scripting (XSS) vulnerabilities if sensitive data is displayed without proper sanitization. While the current analysis shows no unsanitized taint flows, the absence of comprehensive checks on entry points leaves room for potential issues.

In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the lack of fundamental security checks like nonces and capability checks is a critical weakness. The moderate rate of properly escaped output also presents a potential XSS risk. Developers should prioritize implementing these essential security measures to harden the plugin against common web attacks, even if the current analysis doesn't reveal any immediate, exploitable vulnerabilities.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • 44% of outputs not properly escaped
Vulnerabilities
None known

Akouendy Mobile Money Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Akouendy Mobile Money Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
5
Bundled Libraries
0

Output Escaping

56% escaped41 total outputs
Attack Surface

Akouendy Mobile Money Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedakouendy-gateway.php:43
actionwp_enqueue_scriptsakouendy-gateway.php:46
actionbefore_woocommerce_initakouendy-gateway.php:50
actionwoocommerce_blocks_loadedakouendy-gateway.php:60
filterwoocommerce_payment_gatewaysakouendy-gateway.php:76
filterwoocommerce_currenciesakouendy-gateway.php:77
filterwoocommerce_currency_symbolakouendy-gateway.php:78
filterwoocommerce_available_payment_gatewaysakouendy-gateway.php:81
actionwoocommerce_blocks_payment_method_type_registrationakouendy-gateway.php:110
actionwoocommerce_update_options_payment_gatewayspayment-methods\class-wc-gateway-orange-money-senegal-redirect.php:50
actionwoocommerce_update_options_payment_gatewayspayment-methods\class-wc-gateway-wave-senegal.php:49
actionwoocommerce_update_options_payment_gatewayspayment-methods\standalone\class-wc-gateway-orange-money-senegal.php:39
Maintenance & Trust

Akouendy Mobile Money Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 23, 2025
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Akouendy Mobile Money Gateway for WooCommerce Developer Profile

akouendydev

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Akouendy Mobile Money Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/akouendy-woocommerce-orange-money-gateway/assets/css/akouendy-style.css
Script Paths
/wp-content/plugins/akouendy-woocommerce-orange-money-gateway/assets/js/akouendy-pay-widget-v1.0.0.js
Version Parameters
akouendy-woocommerce-orange-money-gateway/assets/js/akouendy-pay-widget-v1.0.0.js?ver=akouendy-woocommerce-orange-money-gateway/assets/css/akouendy-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
akd-orange-money-sn
Data Attributes
data-provider="orange-money-sn-api"
JS Globals
WC_OM_SN_Gateway_Blocks_SupportWC_WAVE_SN_Gateway_Blocks_Support
REST Endpoints
/v1/billing/payment/init/v1/payment/{paymenId}/{applicationId}/v1/billing/{provider}/{token}/v1/billing/{provider}/{token}
FAQ

Frequently Asked Questions about Akouendy Mobile Money Gateway for WooCommerce