
BORICA Payments by BORICA AD Security & Risk Analysis
wordpress.org/plugins/borica-paymentsSimple way of receiving debit and credit card payments by virtual POS.
Is BORICA Payments by BORICA AD Safe to Use in 2026?
Generally Safe
Score 100/100BORICA Payments by BORICA AD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "borica-payments" v3.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by implementing nonce checks and capability checks for its AJAX handlers, and a high percentage of its SQL queries utilize prepared statements, reducing the risk of SQL injection. The absence of file operations and a clean vulnerability history with no known CVEs are also positive indicators. However, the analysis does reveal some areas of concern that warrant attention. Specifically, the presence of three taint flows with unsanitized paths, even though not classified as critical or high severity in this report, represents a potential risk. These flows, if exploited, could lead to unexpected behavior or compromise if they interact with sensitive data or functions. The plugin's external HTTP requests should also be monitored for potential vulnerabilities in the remote services it communicates with.
While the plugin has a clean historical record, which is a significant strength, the identified unsanitized taint flows suggest that continuous vigilance and thorough code review are still necessary. The overall risk is moderate, leaning towards lower due to the lack of historical issues and strong implementation of core security practices. The key recommendation is to investigate and sanitize the identified taint flows to eliminate any potential risk, even if they are not currently critical. Monitoring the security of external dependencies is also prudent. The plugin benefits from a well-defined attack surface and robust internal security mechanisms, but the identified taint flows prevent a completely clean bill of health.
Key Concerns
- Taint flows with unsanitized paths (3)
BORICA Payments by BORICA AD Security Vulnerabilities
BORICA Payments by BORICA AD Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BORICA Payments by BORICA AD Attack Surface
AJAX Handlers 24
WordPress Hooks 33
Maintenance & Trust
BORICA Payments by BORICA AD Maintenance & Trust
Maintenance Signals
Community Trust
BORICA Payments by BORICA AD Alternatives
Monetbil – Mobile Money Gateway for WooCommerce
monetbil-woocommerce-gateway
This is the Mobile Money payment gateway for WooCommerce.
Duitku Pop Payment Gateway
duitku-pop-payment-gateway
Do you want the best solution to accept Credit Cards, e-wallet, and Various Bank Transfers on your website? Our Payment Gateway for WooCommerce plugin …
Autocomplete WooCommerce Orders
autocomplete-woocommerce-orders
Enhance your WooCommerce store with Autocomplete Orders. Automatically complete orders after payment, perfect for virtual goods and subscriptions.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
BORICA Payments by BORICA AD Developer Profile
1 plugin · 500 total installs
How We Detect BORICA Payments by BORICA AD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/borica-payments/css/borica-payment-gateway.css/wp-content/plugins/borica-payments/js/borica-payment-gateway.js/wp-content/plugins/borica-payments/js/borica-payment-gateway-admin.js/wp-content/plugins/borica-payments/js/borica-payment-gateway.js/wp-content/plugins/borica-payments/js/borica-payment-gateway-admin.jsborica-payments/css/borica-payment-gateway.css?ver=borica-payments/js/borica-payment-gateway.js?ver=borica-payments/js/borica-payment-gateway-admin.js?ver=HTML / DOM Fingerprints
borica_payment_gateway_params