
Bangladeshi Payment Gateways – Make Payment Using QR Code Security & Risk Analysis
wordpress.org/plugins/bangladeshi-payment-gatewaysBangladeshi Payment Gateways for WooCommerce.
Is Bangladeshi Payment Gateways – Make Payment Using QR Code Safe to Use in 2026?
Generally Safe
Score 100/100Bangladeshi Payment Gateways – Make Payment Using QR Code has a strong security track record. Known vulnerabilities have been patched promptly.
The "bangladeshi-payment-gateways" plugin v4.0.4 exhibits a generally good security posture, largely due to robust implementation of security best practices. The static analysis reveals a significant number of AJAX handlers, all of which appear to have proper authorization checks, and no REST API routes or shortcodes were identified, minimizing the attack surface. Crucially, no dangerous functions were detected, and all SQL queries are properly prepared, indicating a strong defense against common SQL injection attacks. The high percentage of properly escaped outputs further suggests a good understanding of preventing cross-site scripting (XSS) vulnerabilities.
Despite these strengths, there are a few areas for concern. The taint analysis identified two flows with unsanitized paths, which, while not resulting in critical or high-severity vulnerabilities in this version, represent a potential avenue for exploitation if not addressed. The presence of file operations, though only one, warrants careful scrutiny to ensure it's handled securely. The vulnerability history shows one known CVE, which was promptly patched, and the plugin has a history of missing authorization vulnerabilities, suggesting a past area of weakness that, while seemingly addressed now, warrants continued vigilance. The bundled TCPDF library, if outdated, could also pose a risk.
In conclusion, the plugin has made significant improvements in security, particularly in its handling of AJAX requests and SQL queries. However, the presence of unsanitized paths in the taint analysis and the historical pattern of authorization issues are areas that require ongoing monitoring and diligent security practices to maintain a secure state. The strengths in prepared statements and output escaping are commendable, but the identified taint flows and past vulnerabilities prevent a perfect score.
Key Concerns
- Taint analysis found 2 unsanitized paths
- Vulnerability history: 1 known CVE
- Bundled library: TCPDF
- Presence of file operations
Bangladeshi Payment Gateways – Make Payment Using QR Code Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Appsero <= 1.2.1 - Missing Authorization
Bangladeshi Payment Gateways – Make Payment Using QR Code Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Bangladeshi Payment Gateways – Make Payment Using QR Code Attack Surface
AJAX Handlers 6
WordPress Hooks 29
Maintenance & Trust
Bangladeshi Payment Gateways – Make Payment Using QR Code Maintenance & Trust
Maintenance Signals
Community Trust
Bangladeshi Payment Gateways – Make Payment Using QR Code Alternatives
HitPay Payment Gateway for WooCommerce
hitpay-payment-gateway
HitPay Payment Gateway Plugin allows HitPay merchants to accept PayNow QR, Cards, Apple Pay, Google Pay, WeChatPay, AliPay and GrabPay Payments.
CodeCareBD – Payment Gateway for WooCommerce
codecarebd-bkash-nagad-rocket-payoneer-gateway
CodeCareBD - Payment Gateway plugin integrates bKash, Nagad, Rocket, and Payoneer Payment Gateways with WooCommerce.
6amTech – Payment Gateway for bKash and WC
wc-6amtech-payment-gateway-bkash
6amTech – Payment Gateway for bKash and WooCommerce allows seamless bKash integration, making transactions secure and easy for Bangladeshi customers.
Payment Gateway for M-PESA Open API on WooCommerce
payment-gateway-for-m-pesa-open-api
The plugin enables the customer to have an option of paying merchants using M-PESA mobile money service from a Wordpress site that has WooCommerce plu …
BD Mobile Payments Gateway
bd-mobile-payments-gateway
This plugin is an extension of Woocommerce which added Bangladeshi Taka BDT symble (৳) at WooCommerce plugin where WooCommerce not yet support Banglad …
Bangladeshi Payment Gateways – Make Payment Using QR Code Developer Profile
6 plugins · 5K total installs
How We Detect Bangladeshi Payment Gateways – Make Payment Using QR Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bangladeshi-payment-gateways/dist/css/admin.css/wp-content/plugins/bangladeshi-payment-gateways/dist/js/admin.js/wp-content/plugins/bangladeshi-payment-gateways/dist/css/frontend.css/wp-content/plugins/bangladeshi-payment-gateways/dist/js/frontend.js/wp-content/plugins/bangladeshi-payment-gateways/assets/images/qr-icon.svg/wp-content/plugins/bangladeshi-payment-gateways/dist/js/admin.js/wp-content/plugins/bangladeshi-payment-gateways/dist/js/frontend.js/wp-content/plugins/bangladeshi-payment-gateways/dist/css/admin.css?ver=/wp-content/plugins/bangladeshi-payment-gateways/dist/js/admin.js?ver=/wp-content/plugins/bangladeshi-payment-gateways/dist/css/frontend.css?ver=/wp-content/plugins/bangladeshi-payment-gateways/dist/js/frontend.js?ver=HTML / DOM Fingerprints
bdpg-qr-paymentbdpg-qr-wrapperbdpg-qr-codebdpg-qr-instructions<!-- Bangladeshi Payment Gateways - Make Payment Using QR Code --><!-- Main Plugin File --><!-- Bkash. --><!-- Rocket. -->+26 moredata-qr-code-urldata-account-numberdata-payment-methoddata-order-idbdpg_ajax_object/wp-json/bdpg/v1/order-payment-status[bdpg_qr_payment_gateway]