Autopilot For UPI QR Code Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/autopilot-for-upi-qr-code-payment-gateway

This plugin automates the payment verification process for WooCommerce orders made through the UPI QR Code Payment Gateway for WooCommerce, facilitati …

90 active installs v1.0.5 PHP 5.6+ WP 4.6+ Updated May 23, 2024
automaticqrcodeupiupi-paymentwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Autopilot For UPI QR Code Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Autopilot For UPI QR Code Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "autopilot-for-upi-qr-code-payment-gateway" plugin v1.0.5 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong practices regarding database interactions, with all SQL queries utilizing prepared statements, and all output being properly escaped, significantly reducing the risk of common injection and XSS vulnerabilities. The absence of any known CVEs or recorded vulnerabilities in its history also suggests a degree of security diligence.

However, a significant concern arises from its attack surface. With 5 total entry points, 4 of which lack authentication checks, there is a substantial risk of unauthorized access or malicious data manipulation. Specifically, the 4 unprotected AJAX handlers present a direct pathway for attackers to potentially exploit functionalities without proper user authorization. While taint analysis did not reveal any critical or high severity unsanitized flows, the unprotected entry points could indirectly lead to issues if not handled with extreme care within the plugin's logic.

In conclusion, while the plugin employs good coding practices for SQL and output handling, the large number of unprotected entry points, particularly AJAX handlers, poses a considerable security risk. This weakness outweighs the strengths, making the plugin moderately risky for deployment without further hardening of its access controls.

Key Concerns

  • 4 AJAX handlers without auth checks
  • 1 REST API route without permission callback
Vulnerabilities
None known

Autopilot For UPI QR Code Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Autopilot For UPI QR Code Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
0
48 escaped
Nonce Checks
3
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared12 total queries

Output Escaping

100% escaped48 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
fn_check_qr_scanned (public\class-autopilot-for-upi-qr-code-payment-for-woocommerce-public.php:116)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Autopilot For UPI QR Code Payment Gateway for WooCommerce Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

noprivwp_ajax_check_order_status_upi_paidincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:190
authwp_ajax_check_order_status_upi_paidincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:191
noprivwp_ajax_check_qr_scannedincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:193
authwp_ajax_check_qr_scannedincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:194

REST API Routes 1

POST/wp-json/qaupiwc/v1/update-order/admin\class-autopilot-for-upi-qr-code-payment-for-woocommerce-admin.php:165
WordPress Hooks 14
actionadmin_initadmin\partials\autopilot-for-upi-qr-code-payment-for-woocommerce-admin-display.php:48
actionadmin_initadmin\partials\autopilot-for-upi-qr-code-payment-for-woocommerce-admin-display.php:49
actionadmin_noticesautopilot-for-upi-qr-code-payment-for-woocommerce.php:123
actionplugins_loadedincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:148
actionadmin_enqueue_scriptsincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:162
actionadmin_enqueue_scriptsincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:163
filterrest_pre_echo_responseincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:164
filterupiwc_capture_payment_order_statusincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:166
filterupiwc_order_total_amountincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:167
actionrest_api_initincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:168
actionadmin_menuincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:172
actionwp_enqueue_scriptsincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:187
actionwp_enqueue_scriptsincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:188
actionupiwc_button_show_intervalincludes\class-autopilot-for-upi-qr-code-payment-for-woocommerce.php:189
Maintenance & Trust

Autopilot For UPI QR Code Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMay 23, 2024
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs90
Developer Profile

Autopilot For UPI QR Code Payment Gateway for WooCommerce Developer Profile

Quuantum

3 plugins · 90 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Autopilot For UPI QR Code Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/autopilot-for-upi-qr-code-payment-gateway/admin/css/autopilot-for-upi-qr-code-payment-for-woocommerce-admin.css/wp-content/plugins/autopilot-for-upi-qr-code-payment-gateway/admin/js/autopilot-for-upi-qr-code-payment-for-woocommerce-admin.js/wp-content/plugins/autopilot-for-upi-qr-code-payment-gateway/includes/js/autopilot-for-upi-qr-code-payment-for-woocommerce-public.js
Script Paths
/wp-content/plugins/autopilot-for-upi-qr-code-payment-gateway/admin/js/autopilot-for-upi-qr-code-payment-for-woocommerce-admin.js/wp-content/plugins/autopilot-for-upi-qr-code-payment-gateway/includes/js/autopilot-for-upi-qr-code-payment-for-woocommerce-public.js
Version Parameters
autopilot-for-upi-qr-code-payment-gateway/admin/css/autopilot-for-upi-qr-code-payment-for-woocommerce-admin.css?ver=autopilot-for-upi-qr-code-payment-gateway/admin/js/autopilot-for-upi-qr-code-payment-for-woocommerce-admin.js?ver=autopilot-for-upi-qr-code-payment-gateway/includes/js/autopilot-for-upi-qr-code-payment-for-woocommerce-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
qaupiwc-admin-notice
FAQ

Frequently Asked Questions about Autopilot For UPI QR Code Payment Gateway for WooCommerce