
Aplazo Payment Gateway Security & Risk Analysis
wordpress.org/plugins/aplazo-payment-gatewayAplazo Payment plugin allows users to finalize their purchase buying now and paying later.
Is Aplazo Payment Gateway Safe to Use in 2026?
Generally Safe
Score 99/100Aplazo Payment Gateway has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The aplazo-payment-gateway plugin v1.5.0 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to several secure coding practices, including 100% of SQL queries using prepared statements and 100% of output being properly escaped. There are no identified dangerous functions or raw SQL queries. However, significant concerns arise from the lack of any nonce or capability checks across the identified entry points, including AJAX handlers, REST API routes, and cron events. While the direct attack surface appears limited in terms of entry points, the absence of authentication and authorization mechanisms makes any potential vulnerabilities highly exploitable.
The taint analysis indicates two flows with unsanitized paths, although none reached critical or high severity. This suggests potential vulnerabilities that, while not immediately critical, could be leveraged by attackers if combined with other weaknesses or specific configurations. The vulnerability history, showing one past CVE attributed to 'Missing Authorization', reinforces the concern regarding the plugin's authorization mechanisms. The fact that this past vulnerability is currently unpatched is a significant red flag, even if the current version's analysis doesn't highlight it directly.
In conclusion, while the plugin demonstrates good practices in SQL sanitization and output escaping, the complete absence of nonce and capability checks is a critical weakness. The past 'Missing Authorization' vulnerability and the identified unsanitized paths in the taint analysis further underscore the need for immediate review and remediation of authorization and input sanitization. The plugin's security posture is currently weak due to these fundamental flaws.
Key Concerns
- No nonce checks found on entry points
- No capability checks found on entry points
- Taint flow with unsanitized path (x2)
- Unpatched CVE history (Missing Authorization)
- File operations detected
- External HTTP requests detected
Aplazo Payment Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Aplazo Payment Gateway <= 1.4.3 - Missing Authorization to Unauthenticated Order Status Manipulation
Aplazo Payment Gateway Release Timeline
Aplazo Payment Gateway Code Analysis
Output Escaping
Data Flow Analysis
Aplazo Payment Gateway Attack Surface
WordPress Hooks 19
Scheduled Events 1
Maintenance & Trust
Aplazo Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Aplazo Payment Gateway Alternatives
Tuyo Pay Gateway Plugin
tuyo-pay-gateway
Plugin WooCommerce para la pasarela de pagos Tuyo Pay.
Amazon Pay for WooCommerce
woocommerce-gateway-amazon-payments-advanced
Install the Amazon Pay plugin for your WooCommerce store and take advantage of a seamless checkout experience
Invoice Payment Gateway for WooCommerce
wc-invoice-gateway
The Invoice Payment Gateway for WooCommerce plugin adds an Invoice Payment Gateway feature to the WooCommerce plugin for B2B transactions when instant …
GoDaddy Payments for WooCommerce
godaddy-payments
A payment gateway plugin that enables your U.S. or Canadian business to accept credit card payments directly on your WooCommerce site.
Prodigy Commerce
prodigy-commerce
A powerful alternative to self-hosted eCommerce solutions. Combine WordPress with a full-featured, PCI-compliant platform.
Aplazo Payment Gateway Developer Profile
1 plugin · 300 total installs
How We Detect Aplazo Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aplazo-payment-gateway/assets/js/aplazo-widget/aplazo-widgets.min.js/wp-content/plugins/aplazo-payment-gateway/assets/images/step-1.png/wp-content/plugins/aplazo-payment-gateway/assets/images/step-2.png/wp-content/plugins/aplazo-payment-gateway/assets/images/step-3.png/wp-content/plugins/aplazo-payment-gateway/assets/images/logo-raw.png/wp-content/plugins/aplazo-payment-gateway/assets/images/aplazo-desc-movil/wp-content/plugins/aplazo-payment-gateway/assets/images/aplazo-description.png/wp-content/plugins/aplazo-payment-gateway/assets/css/checkout_aplazo.css/wp-content/plugins/aplazo-payment-gateway/assets/js/aplazo-widget/aplazo-widgets.min.jsaplazo-payment-gateway/style.css?ver=aplazo-payment-gateway/script.js?ver=HTML / DOM Fingerprints
<!-- Aplazo Payment Gateway -->data-merchantiddata-tokendata-langdata-cart-iddata-cart-totaldata-cart-currency+16 moreaplazoConfigaplazoWidgetimages/wp-json/wc-aplazo/v1/create-payment/wp-json/wc-aplazo/v1/payment-status<aplazo-banner></aplazo-banner>