
AllPays.co – Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/allpaysco-payment-gateway-for-woocommerceAccept credit/debit cards, Apple Pay, Google Pay, Venmo and more with no registration. Fast and secure payments through traditional payment methods.
Is AllPays.co – Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100AllPays.co – Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'allpaysco-payment-gateway-for-woocommerce' v1.2.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the vast majority of output is properly escaped, and there are no indications of dangerous functions, file operations, or tainted code flows. This suggests a development team that is conscious of secure coding practices.
However, there are notable areas for improvement. The most significant concern is the presence of one unprotected REST API route. This represents a direct entry point into the plugin that lacks any permission checks, which could potentially be exploited by unauthenticated users. The lack of nonce checks on the identified entry point also presents a risk, as it doesn't protect against common cross-site request forgery (CSRF) attacks.
In conclusion, while the plugin has a solid foundation regarding SQL and output sanitization, the unprotected REST API route and absence of nonce checks are critical weaknesses that require immediate attention. The clean vulnerability history is positive but should not lead to complacency, especially with the identified unprotected entry point.
Key Concerns
- Unprotected REST API route without permission callback
- No nonce checks on entry points
AllPays.co – Payment Gateway for WooCommerce Security Vulnerabilities
AllPays.co – Payment Gateway for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
AllPays.co – Payment Gateway for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 25
Scheduled Events 1
Maintenance & Trust
AllPays.co – Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
AllPays.co – Payment Gateway for WooCommerce Alternatives
Sola Payment Gateway for WooCommerce
woo-cardknox-gateway
Accept payments with the Sola gateway.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Trust Payments Gateway for WooCommerce
trust-payments-hosted-payment-pages-integration
This plugin offers a simple and easy to implement method for merchants to add e-payment capabilities to their WooCommerce online commerce setup.
Nomod for WooCommerce
nomod-for-woocommerce
Accept major cards, Apple Pay, Google Pay, Mada, Tabby & Tamara on your store. Get same-day payouts, no monthly fees & amazing support!
iPOSpays Gateways WC
ipospays-gateways-wc
Accept all major credit cards, Bank, and alternative payment methods like Google Pay, PayPal, and Venmo.
AllPays.co – Payment Gateway for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect AllPays.co – Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/allpaysco-payment-gateway-for-woocommerce/assets/css/payments-settings.css/wp-content/plugins/allpaysco-payment-gateway-for-woocommerce/assets/js/payments-settings.js/wp-content/plugins/allpaysco-payment-gateway-for-woocommerce/assets/js/payments-list.js/wp-content/plugins/allpaysco-payment-gateway-for-woocommerce/assets/js/payments-settings.js/wp-content/plugins/allpaysco-payment-gateway-for-woocommerce/assets/js/payments-list.jsallpaysco-payment-gateway-for-woocommerce/assets/css/payments-settings.css?ver=allpaysco-payment-gateway-for-woocommerce/assets/js/payments-settings.js?ver=allpaysco-payment-gateway-for-woocommerce/assets/js/payments-list.js?ver=HTML / DOM Fingerprints
allpaysco-settingsallpaysco-payment-gateway-logoallpaysco-settings-loading-screen<!-- Default AllPays.co Settings UI --><!-- Legacy AllPays.co Settings UI -->data-allpaysco-payment-gateway-idwindow.allpaysco_settings_params/wp-json/allpaysco/v1/settings