APLUS Interswitch Nigeria WebPAY Security & Risk Analysis

wordpress.org/plugins/aplus-webpay-nigeria

The A+ Interswitch WebPAY Plugin is a simple plugin that helps you accept Verve, MasterCard and VISA cards on your WooCommerce store or donations webs …

0 active installs v1.0.0 PHP + WP 1.0.1+ Updated Jun 2, 2018
interswitchmastercardpayment-gatewayvisawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is APLUS Interswitch Nigeria WebPAY Safe to Use in 2026?

Generally Safe

Score 85/100

APLUS Interswitch Nigeria WebPAY has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'aplus-webpay-nigeria' v1.0.0 plugin exhibits a generally positive security posture, demonstrating good practices in several key areas. The complete absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure codebase. Furthermore, the static analysis reveals no critical or high-severity taint flows, no dangerous functions, no file operations, and all SQL queries are properly prepared. This indicates a robust approach to preventing common injection vulnerabilities and ensuring data integrity. The plugin also has a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing potential entry points for attackers. The presence of external HTTP requests is a minor point of concern, as it can sometimes be a vector for SSRF or other attacks if not handled carefully, though no specific issues are flagged here. However, the static analysis does highlight weaknesses. Notably, the lack of nonce checks and capability checks on the identified entry points (even though there are none currently) presents a significant future risk if entry points are added without proper authorization. Additionally, with only 62% of output properly escaped, there is a moderate risk of cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is used in these unescaped outputs. The taint analysis indicating unsanitized paths in the two analyzed flows is concerning, even though they are not classified as critical or high severity, suggesting potential for issues if these paths are exposed to user input.

Key Concerns

  • Unsanitized paths in taint flows
  • Missing nonce checks
  • Missing capability checks
  • Moderate output escaping (38% unescaped)
  • External HTTP requests
Vulnerabilities
None known

APLUS Interswitch Nigeria WebPAY Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

APLUS Interswitch Nigeria WebPAY Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

62% escaped13 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
essl_wc_interswitch_webpay_init (aplus-webpay-nigeria.php:211)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

APLUS Interswitch Nigeria WebPAY Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedaplus-webpay-nigeria.php:15
actionwoocommerce_receipt_essl_webpay_gatewayaplus-webpay-nigeria.php:253
actionwoocommerce_api_wc_essl_webpay_gatewayaplus-webpay-nigeria.php:257
actionbefore_woocommerce_payaplus-webpay-nigeria.php:260
actionadmin_menuaplus-webpay-nigeria.php:829
actionwpaplus-webpay-nigeria.php:857
filterwoocommerce_payment_gatewaysaplus-webpay-nigeria.php:868
filterwoocommerce_currenciesaplus-webpay-nigeria.php:880
filterwoocommerce_currency_symbolaplus-webpay-nigeria.php:893
filterplugin_action_linksaplus-webpay-nigeria.php:915
filterplugin_action_linksaplus-webpay-nigeria.php:939
actionadmin_noticesaplus-webpay-nigeria.php:979
Maintenance & Trust

APLUS Interswitch Nigeria WebPAY Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 2, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

APLUS Interswitch Nigeria WebPAY Developer Profile

Jon Jazzy

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect APLUS Interswitch Nigeria WebPAY

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aplus-webpay-nigeria/assets/images/card_details.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/mastercard.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/new_webpay_3.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/new_webpay_6.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/old_webpay.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/old_webpay_1.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/old_webpay_2.png/wp-content/plugins/aplus-webpay-nigeria/assets/images/old_webpay_3.png+6 more

HTML / DOM Fingerprints

CSS Classes
xl63xl65
Data Attributes
widthheight
Shortcode Output
<p style="text-align: center;"><strong><u>MAKING ONLINE PAYMENTS ON Issues paying online? Please contact us at There are three major ATM card companies in Nigeria. They are:Most of the ATM cards issued by Nigerian banks are usually from one of these three companies. Some of these cards include Interswitch
FAQ

Frequently Asked Questions about APLUS Interswitch Nigeria WebPAY