
Avify Security & Risk Analysis
wordpress.org/plugins/avifyConnect your WooCommerce account to Avify and send all your orders to one centralized inventory.
Is Avify Safe to Use in 2026?
Generally Safe
Score 100/100Avify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "avify" v1.3.8 plugin presents a mixed security profile. On the positive side, it has no known historical vulnerabilities (CVEs) and its static analysis reveals no direct use of dangerous functions or external HTTP requests. Furthermore, all detected SQL queries are properly prepared, mitigating common injection risks. The plugin also utilizes prepared statements for SQL, which is a strong security practice. However, several concerning aspects emerge from the code analysis. A significant weakness is the complete absence of nonce checks and capability checks, which are fundamental security mechanisms for preventing CSRF attacks and unauthorized actions. The taint analysis highlights two high-severity flows with unsanitized paths, indicating potential for information disclosure or other vulnerabilities if these paths are exploited, even though they are not currently classified as critical.
The lack of nonce and capability checks is a critical oversight, leaving the plugin vulnerable to cross-site request forgery (CSRF) and unauthorized access if any of its entry points can be triggered by unauthenticated or lower-privileged users. The high-severity taint flows, while not resulting in critical vulnerabilities in this analysis, suggest that the plugin is handling potentially sensitive data or paths without adequate sanitization, which could be a precursor to future issues or be exploitable in conjunction with other weaknesses. The moderate output escaping (52%) also presents a moderate risk of cross-site scripting (XSS) vulnerabilities. While the vulnerability history is clean, the presence of these code-level weaknesses suggests that the plugin may not be as robust as its history implies, and future vulnerabilities could arise if these issues are not addressed.
Key Concerns
- High severity taint flow with unsanitized paths
- High severity taint flow with unsanitized paths
- Moderate output escaping (52% proper)
- Zero nonce checks
- Zero capability checks
Avify Security Vulnerabilities
Avify Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Avify Attack Surface
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Avify Maintenance & Trust
Maintenance Signals
Community Trust
Avify Alternatives
Custom Payment Gateways for WooCommerce
custom-payment-gateways-woocommerce
Custom payment gateways for WooCommerce - create custom payment gateways to never miss out any payments for your WooCommerce Store.
WC Order Test
woo-order-test
Test your WooCommerce order process in seconds to ensure your checkout works correctly.
Up2pay e-Transactions WooCommerce Payment Gateway
e-transactions-wc
This plugin is a Up2pay e-Transactions payment gateway for WooCommerce 4.x
myPOS Checkout
mypos-virtual-for-woocommerce
One-click checkout with instant settlement. Accept all major cards, Apple Pay and Google Pay. No setup costs or monthly fees.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Avify Developer Profile
1 plugin · 80 total installs
How We Detect Avify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/avify/avify-checkout.css/wp-content/plugins/avify/avify-checkout.js/wp-content/plugins/avify/avify-custom-options.css/wp-content/plugins/avify/avify-custom-options.js/wp-content/plugins/avify/avify-payments-gateway.css/wp-content/plugins/avify/avify-payments-gateway.js/wp-content/plugins/avify/avify-shipping.css/wp-content/plugins/avify/avify-shipping.js+1 more/wp-content/plugins/avify/avify-checkout.js/wp-content/plugins/avify/avify-custom-options.js/wp-content/plugins/avify/avify-payments-gateway.js/wp-content/plugins/avify/avify-shipping.jsavify/avify-checkout.css?ver=avify/avify-checkout.js?ver=avify/avify-custom-options.css?ver=avify/avify-custom-options.js?ver=avify/avify-payments-gateway.css?ver=avify/avify-payments-gateway.js?ver=avify/avify-shipping.css?ver=avify/avify-shipping.js?ver=avify/avify-styles.css?ver=HTML / DOM Fingerprints
avify-checkout-formavify-custom-options-field<!-- Avify Gateway --><!-- Avify Orders --><!-- Avify Shipping --><!-- Avify Rest -->+3 moredata-avify-optionavify_checkout_params/wp-json/avify/v1/orders/wp-json/avify/v1/shipping-methods/wp-json/avify/v1/payment-status[avify_checkout]