Bayarcash for Fluent Forms Security & Risk Analysis

wordpress.org/plugins/bayarcash-for-fluent-forms

Integrate Bayarcash payment gateway with Fluent Forms to accept payments in Malaysia via FPX, DuitNow, and other local payment methods.

60 active installs v2.0.4 PHP 7.4+ WP 5.0+ Updated Nov 5, 2025
bayarcashfluent-formsfpxmalaysia-paymentpayment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bayarcash for Fluent Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Bayarcash for Fluent Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "bayarcash-for-fluent-forms" plugin version 2.0.4 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, having no recorded vulnerabilities (CVEs), and performing a significant number of output escaps. The absence of dangerous functions and file operations is also commendable. However, there are notable concerns regarding its attack surface. The plugin exposes 7 AJAX handlers, with 2 of them lacking proper authentication checks. This is a significant risk as it could allow unauthenticated users to trigger potentially sensitive actions. While taint analysis revealed no critical or high severity unsanitized paths, the unprotected AJAX endpoints create an avenue for exploitation that could be amplified if sensitive data is processed or modified through them. The presence of 14 nonce checks and 2 capability checks is positive, but they are not applied to all entry points, particularly the 2 AJAX handlers. The plugin's history of zero known vulnerabilities is a strong indicator of generally sound development, but the current findings of unprotected AJAX handlers suggest that continued vigilance is necessary.

Key Concerns

  • AJAX handlers without auth checks
  • Moderate output escaping coverage (70%)
Vulnerabilities
None known

Bayarcash for Fluent Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bayarcash for Fluent Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
232
554 escaped
Nonce Checks
14
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared2 total queries

Output Escaping

70% escaped786 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
csf_export (includes\codestar-framework\functions\actions.php:62)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Bayarcash for Fluent Forms Attack Surface

Entry Points7
Unprotected2

AJAX Handlers 7

authwp_ajax_save_bayarcash_settingsincludes\admin\global-settings.php:99
authwp_ajax_verify_bayarcash_tokenincludes\admin\global-settings.php:108
authwp_ajax_csf-get-iconsincludes\codestar-framework\functions\actions.php:50
authwp_ajax_csf-exportincludes\codestar-framework\functions\actions.php:87
authwp_ajax_csf-importincludes\codestar-framework\functions\actions.php:123
authwp_ajax_csf-resetincludes\codestar-framework\functions\actions.php:150
authwp_ajax_csf-chosenincludes\codestar-framework\functions\actions.php:189
WordPress Hooks 52
actionadmin_noticesbayarcash-for-fluent-forms.php:26
actionadmin_noticesbayarcash-for-fluent-forms.php:39
actionwp_enqueue_scriptsbayarcash-for-fluent-forms.php:104
actioninitbayarcash-for-fluent-forms.php:152
actionadmin_noticesbayarcash-for-fluent-forms.php:156
filterfluentform/payment_field_typesincludes\add-gateway-fee.php:19
filterfluent_editor_init_payment_field_typesincludes\add-gateway-fee.php:20
actionfluentform/loadedincludes\add-gateway-fee.php:90
filterfluentform/available_payment_methodsincludes\class-register.php:18
actionwp_enqueue_scriptsincludes\codestar-framework\classes\abstract.class.php:21
actionadmin_menuincludes\codestar-framework\classes\admin-options.class.php:107
actionadmin_bar_menuincludes\codestar-framework\classes\admin-options.class.php:108
actionnetwork_admin_menuincludes\codestar-framework\classes\admin-options.class.php:112
filteradmin_footer_textincludes\codestar-framework\classes\admin-options.class.php:432
actionadd_meta_boxes_commentincludes\codestar-framework\classes\comment-options.class.php:38
actionedit_commentincludes\codestar-framework\classes\comment-options.class.php:39
actioncustomize_registerincludes\codestar-framework\classes\customize-options.class.php:44
actioncustomize_save_afterincludes\codestar-framework\classes\customize-options.class.php:45
actionwp_enqueue_scriptsincludes\codestar-framework\classes\customize-options.class.php:49
actionadd_meta_boxesincludes\codestar-framework\classes\metabox-options.class.php:50
actionsave_postincludes\codestar-framework\classes\metabox-options.class.php:51
actionedit_attachmentincludes\codestar-framework\classes\metabox-options.class.php:52
actionwp_nav_menu_item_custom_fieldsincludes\codestar-framework\classes\nav-menu-options.class.php:32
actionwp_update_nav_menu_itemincludes\codestar-framework\classes\nav-menu-options.class.php:33
filterwp_edit_nav_menu_walkerincludes\codestar-framework\classes\nav-menu-options.class.php:35
actionadmin_initincludes\codestar-framework\classes\profile-options.class.php:32
actionshow_user_profileincludes\codestar-framework\classes\profile-options.class.php:44
actionedit_user_profileincludes\codestar-framework\classes\profile-options.class.php:45
actionpersonal_options_updateincludes\codestar-framework\classes\profile-options.class.php:47
actionedit_user_profile_updateincludes\codestar-framework\classes\profile-options.class.php:48
actionafter_setup_themeincludes\codestar-framework\classes\setup.class.php:73
actioninitincludes\codestar-framework\classes\setup.class.php:74
actionswitch_themeincludes\codestar-framework\classes\setup.class.php:75
actionadmin_enqueue_scriptsincludes\codestar-framework\classes\setup.class.php:76
actionwp_enqueue_scriptsincludes\codestar-framework\classes\setup.class.php:77
actionwp_headincludes\codestar-framework\classes\setup.class.php:78
filteradmin_body_classincludes\codestar-framework\classes\setup.class.php:79
actionadmin_footerincludes\codestar-framework\classes\shortcode-options.class.php:47
actioncustomize_controls_print_footer_scriptsincludes\codestar-framework\classes\shortcode-options.class.php:48
actionelementor/editor/before_enqueue_scriptsincludes\codestar-framework\classes\shortcode-options.class.php:59
actionelementor/editor/footerincludes\codestar-framework\classes\shortcode-options.class.php:60
actionelementor/editor/footerincludes\codestar-framework\classes\shortcode-options.class.php:61
actionenqueue_block_editor_assetsincludes\codestar-framework\classes\shortcode-options.class.php:258
actionmedia_buttonsincludes\codestar-framework\classes\shortcode-options.class.php:262
actionadmin_initincludes\codestar-framework\classes\taxonomy-options.class.php:41
actionadmin_footerincludes\codestar-framework\fields\icon\icon.php:41
actioncustomize_controls_print_footer_scriptsincludes\codestar-framework\fields\icon\icon.php:42
actionadmin_print_footer_scriptsincludes\codestar-framework\fields\link\link.php:65
actionprint_default_editor_scriptsincludes\codestar-framework\fields\wp_editor\wp_editor.php:62
actionadmin_menuincludes\codestar-framework\views\welcome.php:19
filterplugin_action_linksincludes\codestar-framework\views\welcome.php:20
filterplugin_row_metaincludes\codestar-framework\views\welcome.php:21
Maintenance & Trust

Bayarcash for Fluent Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 5, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Bayarcash for Fluent Forms Developer Profile

Bayarcash

3 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bayarcash for Fluent Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bayarcash-for-fluent-forms/includes/js/bayarcash-fluent-forms.js/wp-content/plugins/bayarcash-for-fluent-forms/includes/codestar-framework/classes/setup.class.php
Script Paths
includes/js/bayarcash-fluent-forms.js
Version Parameters
bayarcash-fluent-forms.js?ver=

HTML / DOM Fingerprints

JS Globals
bayarcashFF
FAQ

Frequently Asked Questions about Bayarcash for Fluent Forms