Appibase Payments Security & Risk Analysis

wordpress.org/plugins/appibase

Appibase hosted checkout gateway for Algeria CIB/Edahabia payments in WooCommerce.

0 active installs v1.1.0 PHP 7.4+ WP 5.8+ Updated Feb 3, 2026
algeriecibedahabiapaymentsatim
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Appibase Payments Safe to Use in 2026?

Generally Safe

Score 100/100

Appibase Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The appibase plugin v1.1.0 demonstrates some strong security practices, particularly in its handling of SQL queries and output escaping, with 100% of SQL queries using prepared statements and all outputs being properly escaped. The absence of known vulnerabilities in its history is also a positive indicator. However, the plugin presents a significant security concern due to its single unprotected REST API route. This route represents an entry point into the plugin's functionality that is accessible without any authentication or permission checks. The static analysis also identified one file operation, which, while not inherently dangerous, could become a vector for abuse if not properly secured, especially when coupled with an unprotected entry point. The lack of any recorded vulnerabilities in the past is encouraging, suggesting a generally cautious development approach, but the identified unprotected REST API route requires immediate attention.

Key Concerns

  • Unprotected REST API route
  • File operation present
Vulnerabilities
None known

Appibase Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Appibase Payments Release Timeline

v1.1.0Current
Code Analysis
Analyzed Apr 16, 2026

Appibase Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
56 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped56 total outputs
Attack Surface
1 unprotected

Appibase Payments Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/appibase/v1/webhookincludes/class-appibase-webhook-handler.php:13
WordPress Hooks 20
actionplugins_loadedappibase.php:44
actionplugins_loadedappibase.php:48
filterplugin_dataappibase.php:50
actionadmin_noticesincludes/class-appibase-plugin.php:11
filterwoocommerce_payment_gatewaysincludes/class-appibase-plugin.php:28
actionwoocommerce_api_appibase_webhookincludes/class-appibase-plugin.php:29
actionwoocommerce_api_appibase_returnincludes/class-appibase-plugin.php:30
actionwoocommerce_blocks_loadedincludes/class-appibase-plugin.php:31
actionrest_api_initincludes/class-appibase-plugin.php:35
actiontemplate_redirectincludes/class-appibase-plugin.php:36
actionwoocommerce_view_orderincludes/class-appibase-plugin.php:37
actionbefore_woocommerce_initincludes/class-appibase-plugin.php:38
filterwoocommerce_order_actionsincludes/class-appibase-plugin.php:39
actionwoocommerce_order_action_appibase_sync_paymentincludes/class-appibase-plugin.php:40
filterwoocommerce_thankyou_order_received_titleincludes/class-appibase-plugin.php:41
filterwoocommerce_thankyou_order_received_textincludes/class-appibase-plugin.php:42
filterwoocommerce_gateway_iconincludes/class-appibase-plugin.php:43
actionwoocommerce_blocks_payment_method_type_registrationincludes/class-appibase-plugin.php:65
actionadmin_enqueue_scriptsincludes/gateway/class-appibase-gateway.php:60
actionadmin_noticesincludes/gateway/class-appibase-gateway.php:61
Maintenance & Trust

Appibase Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 3, 2026
PHP min version7.4
Downloads124

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Appibase Payments Developer Profile

appibase dev

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Appibase Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/appibase/assets/css/appibase-admin.css/wp-content/plugins/appibase/assets/js/appibase-admin.js
Script Paths
/wp-content/plugins/appibase/assets/js/appibase-admin.js
Version Parameters
appibase/assets/css/appibase-admin.css?ver=appibase/assets/js/appibase-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
appibase-webhook-url
Data Attributes
data-appibase-admin
JS Globals
appibaseAdmin
FAQ

Frequently Asked Questions about Appibase Payments