
BD Mobile Payments Gateway Security & Risk Analysis
wordpress.org/plugins/bd-mobile-payments-gatewayThis plugin is an extension of Woocommerce which added Bangladeshi Taka BDT symble (৳) at WooCommerce plugin where WooCommerce not yet support Banglad …
Is BD Mobile Payments Gateway Safe to Use in 2026?
Generally Safe
Score 85/100BD Mobile Payments Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "bd-mobile-payments-gateway" plugin v1.1 appears to have a generally good security posture. The absence of known CVEs, zero critical or high-severity vulnerabilities in its history, and the lack of identified dangerous functions or raw SQL queries are positive indicators. Furthermore, the static analysis reveals a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper checks. All SQL queries utilize prepared statements, which is a strong security practice.
However, there are areas for concern. A significant portion of output (52%) is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if the data being output is user-controlled or originates from an untrusted source. The lack of any identified taint flows in the static analysis might be due to the limited scope of the analysis or the nature of the plugin's functionality, but the unescaped output presents a tangible risk. Additionally, the complete absence of nonce and capability checks across all potential entry points is a significant weakness, even with a seemingly small attack surface. This makes the plugin susceptible to CSRF attacks and unauthorized actions if any functionality were to be exposed in the future.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices regarding SQL and attack surface minimization, the substantial amount of unescaped output and the complete lack of authorization checks represent critical weaknesses. These findings suggest that the plugin, despite its current apparent safety, has the potential for serious security flaws if not addressed. The developer should prioritize addressing the unescaped output and implementing robust authorization mechanisms.
Key Concerns
- Significant unescaped output detected
- No nonce checks implemented
- No capability checks implemented
BD Mobile Payments Gateway Security Vulnerabilities
BD Mobile Payments Gateway Code Analysis
Output Escaping
BD Mobile Payments Gateway Attack Surface
WordPress Hooks 10
Maintenance & Trust
BD Mobile Payments Gateway Maintenance & Trust
Maintenance Signals
Community Trust
BD Mobile Payments Gateway Alternatives
Payment Gateway for M-PESA Open API on WooCommerce
payment-gateway-for-m-pesa-open-api
The plugin enables the customer to have an option of paying merchants using M-PESA mobile money service from a Wordpress site that has WooCommerce plu …
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
BD Mobile Payments Gateway Developer Profile
1 plugin · 10 total installs
How We Detect BD Mobile Payments Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bd-mobile-payments-gateway/includes/gateways/bkash/class-wc-gateway-bKash.php/wp-content/plugins/bd-mobile-payments-gateway/includes/gateways/dbblmb/class-wc-gateway-dbblmb.php