
Bayarcash WooCommerce Security & Risk Analysis
wordpress.org/plugins/bayarcash-wcAccept online payment & QR from Malaysia. Currently, Bayarcash support FPX, Direct Debit and DuitNow payment channels.
Is Bayarcash WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Bayarcash WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The bayarcash-wc plugin version 4.3.14 exhibits a generally strong security posture with a notable absence of critical or high-severity vulnerabilities identified in both static analysis and taint flows. The plugin demonstrates good practices by implementing capability checks and nonce checks for its entry points, and a high percentage of output escaping is present, which helps mitigate cross-site scripting risks. The static analysis also indicates no dangerous functions are being used.
However, there are several areas that warrant attention. The single SQL query identified is not using prepared statements, which poses a significant risk of SQL injection, especially if the query involves user-supplied input. While taint analysis did not reveal any critical or high-severity issues, the presence of three flows with unsanitized paths is a concern and suggests potential for vulnerabilities if these paths are ever exposed to untrusted input. Furthermore, the plugin bundles external libraries (Lodash and Guzzle), which, if not regularly updated and audited, could introduce their own vulnerabilities. The vulnerability history, despite having no currently unpatched CVEs, shows a past medium-severity vulnerability related to missing authorization, indicating a historical weakness that users should be aware of.
In conclusion, bayarcash-wc v4.3.14 has strengths in its authorization and output escaping mechanisms, and currently lacks critical exploitable flaws. Nevertheless, the unescaped SQL query and the identified unsanitized paths are significant risks that require immediate attention. Regular updates and audits of bundled libraries are also recommended to maintain a robust security profile.
Key Concerns
- SQL query not using prepared statements
- Flows with unsanitized paths identified
- Bundled external libraries (Lodash, Guzzle)
- Past medium severity vulnerability (Missing Authorization)
Bayarcash WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bayarcash WooCommerce <= 4.3.12 - Missing Authorization
Bayarcash WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Bayarcash WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 53
Scheduled Events 2
Maintenance & Trust
Bayarcash WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Bayarcash WooCommerce Alternatives
toyyibPay for WooCommerce
toyyibpay-for-woocommerce
The official toyyibPay payment gateway plugin for WooCommerce — enabling Malaysian merchants to accept secure online payments with ease.
Bayarcash GiveWP
bayarcash-givewp
Accept online donation from Malaysia and international payments. Supports FPX, DuitNow, NETS, Alipay, WeChat Pay, PromptPay and more payment channels.
RinggitPay for WooCommerce
ringgitpay
RinggitPay payment gateway plugin for WooCommerce
Bayarcash for FluentCart
bayarcash-for-fluentcart
Accept payments via Bayarcash payment gateway for FluentCart. Supports FPX, DuitNow QR, and other Malaysian payment methods.
GoCardless for WooCommerce
woocommerce-gateway-gocardless
Extends WooCommerce with a GoCardless gateway. A GoCardless merchant account is required.
Bayarcash WooCommerce Developer Profile
5 plugins · 840 total installs
How We Detect Bayarcash WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bayarcash-wc/assets/css/backend.css/wp-content/plugins/bayarcash-wc/assets/css/frontend.css/wp-content/plugins/bayarcash-wc/assets/js/backend.js/wp-content/plugins/bayarcash-wc/assets/js/frontend.js/wp-content/plugins/bayarcash-wc/assets/js/backend/app.js/wp-content/plugins/bayarcash-wc/assets/js/frontend/app.js/wp-content/plugins/bayarcash-wc/assets/js/backend.js/wp-content/plugins/bayarcash-wc/assets/js/frontend.js/wp-content/plugins/bayarcash-wc/assets/js/backend/app.js/wp-content/plugins/bayarcash-wc/assets/js/frontend/app.jsbayarcash-wc/assets/css/backend.css?ver=bayarcash-wc/assets/css/frontend.css?ver=bayarcash-wc/assets/js/backend.js?ver=bayarcash-wc/assets/js/frontend.js?ver=bayarcash-wc/assets/js/backend/app.js?ver=bayarcash-wc/assets/js/frontend/app.js?ver=HTML / DOM Fingerprints
bayarcash-wc-settings-pagebayarcash-wc-backend-appbayarcash-wc-frontend-app<!-- Bayarcash WC Settings Page --><!-- Bayarcash WC Backend App --><!-- Bayarcash WC Frontend App -->data-bayarcash-wc-settingsdata-bayarcash-wc-appwindow.BayarcashWCSettingswindow.BayarcashWCBackendAppwindow.BayarcashWCFriendendAppvar BayarcashWCSettingsvar BayarcashWCBackendAppvar BayarcashWCFriendendApp/wp-json/bayarcash-wc/v1/settings/wp-json/bayarcash-wc/v1/payment-status[bayarcash_payment_form][bayarcash_order_summary]