AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Security & Risk Analysis

wordpress.org/plugins/alpha-pay-wechat-pay-alipay-for-woocommerce

Allow Canadian merchants to connect all the mainstream payment channels like WeChat Pay, Alipay, UnionPay, Visa, and MasterCard upon single activation …

50 active installs v1.10.0 PHP 5.6+ WP 4.0+ Updated Mar 13, 2026
alipaycredit-cardunionpaywechat-paywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Safe to Use in 2026?

Generally Safe

Score 100/100

AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The absence of known vulnerabilities in its history is also a positive indicator, suggesting a generally stable development process. However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers with no authentication or capability checks. This represents a substantial attack surface that could allow unauthenticated users to trigger potentially sensitive actions within the plugin.

Despite the lack of critical taint flows or dangerous functions identified, the unprotected AJAX endpoints are a significant weakness. The absence of nonce checks and capability checks for these entry points means that any user, including unauthenticated ones, could potentially interact with these handlers. While the static analysis didn't reveal specific exploitable flows, the potential for abuse exists solely due to the lack of authorization. The vulnerability history being clean is a positive sign, but it doesn't negate the risks presented by the current static analysis findings. Overall, while the plugin has some strong security foundations, the unprotected AJAX handlers represent a critical oversight that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
4
Bundled Libraries
0

Output Escaping

92% escaped26 total outputs
Attack Surface
2 unprotected

AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_alphapay_order_statusincludes\class-wc-alphapay-gateway.php:51
noprivwp_ajax_alphapay_order_statusincludes\class-wc-alphapay-gateway.php:52
WordPress Hooks 15
actionwoocommerce_api_wc_alphapay_notifyincludes\class-wc-alphapay-gateway-alipay.php:63
actionwp_enqueue_scriptsincludes\class-wc-alphapay-gateway-alipay.php:64
actionwoocommerce_api_wc_alphapay_notifyincludes\class-wc-alphapay-gateway-credit-card.php:63
actionwp_enqueue_scriptsincludes\class-wc-alphapay-gateway-credit-card.php:64
actionwoocommerce_api_wc_alphapay_notifyincludes\class-wc-alphapay-gateway-unionpay-express.php:63
actionwp_enqueue_scriptsincludes\class-wc-alphapay-gateway-unionpay-express.php:64
actionwoocommerce_api_wc_alphapay_notifyincludes\class-wc-alphapay-gateway-unionpay.php:63
actionwp_enqueue_scriptsincludes\class-wc-alphapay-gateway-unionpay.php:64
actionwoocommerce_api_wc_alphapay_notifyincludes\class-wc-alphapay-gateway.php:54
actionwp_enqueue_scriptsincludes\class-wc-alphapay-gateway.php:55
actioninitwoocommerce-gateway-alphapay.php:124
actioninitwoocommerce-gateway-alphapay.php:125
actionwp_enqueue_scriptswoocommerce-gateway-alphapay.php:126
filterwoocommerce_payment_gatewayswoocommerce-gateway-alphapay.php:168
actionwoocommerce_admin_order_data_after_billing_addresswoocommerce-gateway-alphapay.php:196
Maintenance & Trust

AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付) Developer Profile

AlphaPay

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alpha-pay-wechat-pay-alipay-for-woocommerce/assets/css/alphapay-style.css/wp-content/plugins/alpha-pay-wechat-pay-alipay-for-woocommerce/assets/js/qrcode.js
Script Paths
/wp-content/plugins/alpha-pay-wechat-pay-alipay-for-woocommerce/assets/js/qrcode.js
Version Parameters
alpha-pay-wechat-pay-alipay-for-woocommerce/assets/css/alphapay-style.css?ver=qrcode.js?ver=

HTML / DOM Fingerprints

CSS Classes
right-float
FAQ

Frequently Asked Questions about AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付)