
Bayarcash for FluentCart Security & Risk Analysis
wordpress.org/plugins/bayarcash-for-fluentcartAccept payments via Bayarcash payment gateway for FluentCart. Supports FPX, DuitNow QR, and other Malaysian payment methods.
Is Bayarcash for FluentCart Safe to Use in 2026?
Generally Safe
Score 100/100Bayarcash for FluentCart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bayarcash-for-fluentcart" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, external HTTP requests, file operations, and SQL queries not using prepared statements are all positive indicators. The low number of entry points and the fact that none are unprotected further bolster its security. The output escaping rate of 85% is also commendable, though there's room for improvement.
However, a significant concern arises from the complete lack of nonce checks and capability checks. While the attack surface appears minimal in terms of entry points, these security mechanisms are fundamental for protecting against various types of attacks, including CSRF and unauthorized actions, especially if any new entry points are introduced or if existing ones are implicitly used. The vulnerability history shows no recorded issues, which is excellent, but it's crucial to remember that this indicates past performance and doesn't guarantee future invulnerability. The presence of Guzzle as a bundled library, while common, warrants monitoring for potential vulnerabilities in that specific library itself.
Overall, the plugin demonstrates good foundational security practices with respect to data handling and entry point protection. The primary area for improvement and potential risk lies in the absence of robust authorization checks (nonces and capabilities) on its functionalities, even with the current limited attack surface. Continuous monitoring of bundled libraries and vigilance in adding these missing security checks will be key to maintaining its secure status.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Bundled library (Guzzle) needs monitoring
- 15% of outputs not properly escaped
Bayarcash for FluentCart Security Vulnerabilities
Bayarcash for FluentCart Code Analysis
Bundled Libraries
Output Escaping
Bayarcash for FluentCart Attack Surface
WordPress Hooks 5
Maintenance & Trust
Bayarcash for FluentCart Maintenance & Trust
Maintenance Signals
Community Trust
Bayarcash for FluentCart Alternatives
toyyibPay for WooCommerce
toyyibpay-for-woocommerce
The official toyyibPay payment gateway plugin for WooCommerce — enabling Malaysian merchants to accept secure online payments with ease.
Bayarcash for Fluent Forms
bayarcash-for-fluent-forms
Integrate Bayarcash payment gateway with Fluent Forms to accept payments in Malaysia via FPX, DuitNow, and other local payment methods.
RinggitPay for WooCommerce
ringgitpay
RinggitPay payment gateway plugin for WooCommerce
Bayarcash WooCommerce
bayarcash-wc
Accept online payment & QR from Malaysia. Currently, Bayarcash support FPX, Direct Debit and DuitNow payment channels.
Payex Payment Gateway for Woocommerce
payex-payment-gateway-for-woocommerce
With Payex, you can now accept payments from Malaysia & oversea customers via FPX, Cards (Visa/MC/UnionPay), EWallets, Instalments and Subscriptio …
Bayarcash for FluentCart Developer Profile
3 plugins · 60 total installs
How We Detect Bayarcash for FluentCart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bayarcash-for-fluentcart/assets/img/bayarcash-icon.pngbayarcash-for-fluentcart/assets/img/bayarcash-icon.png?ver=HTML / DOM Fingerprints
bayarcash-iconbayarcash-logodata-payment-gateway="bayarcash"