
FPX Payment for WPSmartPay (Billplz) Security & Risk Analysis
wordpress.org/plugins/billplz-for-wpsmartpayAccept payment in WPSmartPay by using Billplz.
Is FPX Payment for WPSmartPay (Billplz) Safe to Use in 2026?
Generally Safe
Score 85/100FPX Payment for WPSmartPay (Billplz) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "billplz-for-wpsmartpay" plugin v1.0.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, avoiding dangerous functions, and having no recorded vulnerability history or known CVEs. This suggests a generally secure development approach and a lack of historical security issues, which is encouraging.
However, there are significant concerns stemming from the static analysis. The plugin has a REST API route that lacks permission callbacks, creating an unprotected entry point into the application. Furthermore, only 50% of its output is properly escaped, leaving the potential for cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on AJAX handlers, though the count is zero, is a missed opportunity for robust security, especially if functionality is added later.
Overall, while the plugin's clean vulnerability history and proper SQL handling are strengths, the identified unprotected REST API endpoint and potential for XSS due to insufficient output escaping represent critical areas for immediate attention. These issues create a tangible attack surface that could be exploited if not addressed.
Key Concerns
- Unprotected REST API route
- Half of outputs not properly escaped
FPX Payment for WPSmartPay (Billplz) Security Vulnerabilities
FPX Payment for WPSmartPay (Billplz) Release Timeline
FPX Payment for WPSmartPay (Billplz) Code Analysis
Output Escaping
FPX Payment for WPSmartPay (Billplz) Attack Surface
REST API Routes 1
WordPress Hooks 9
Maintenance & Trust
FPX Payment for WPSmartPay (Billplz) Maintenance & Trust
Maintenance Signals
Community Trust
FPX Payment for WPSmartPay (Billplz) Alternatives
Billplz Addon for Contact Form 7
billplz-for-contact-form-7
Integrates Billplz with Contact Form 7. Start accepting payment with Contact Form 7 & Billplz today.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
woocommerce-exporter
Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.
FPX Payment for WPSmartPay (Billplz) Developer Profile
6 plugins · 130 total installs
How We Detect FPX Payment for WPSmartPay (Billplz)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/billplz-for-wpsmartpay/assets/img/billplz.pngHTML / DOM Fingerprints
text-uppercasetext-infomy-1/billplz-smartpay/v1/bwpsp-callback