
BORICA Payments by BORICA AD Security & Risk Analysis
wordpress.org/plugins/borica-paymentsSimple way of receiving debit and credit card payments by virtual POS.
Is BORICA Payments by BORICA AD Safe to Use in 2026?
Generally Safe
Score 100/100BORICA Payments by BORICA AD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "borica-payments" v3.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by implementing nonce checks and capability checks for its AJAX handlers, and a high percentage of its SQL queries utilize prepared statements, reducing the risk of SQL injection. The absence of file operations and a clean vulnerability history with no known CVEs are also positive indicators. However, the analysis does reveal some areas of concern that warrant attention. Specifically, the presence of three taint flows with unsanitized paths, even though not classified as critical or high severity in this report, represents a potential risk. These flows, if exploited, could lead to unexpected behavior or compromise if they interact with sensitive data or functions. The plugin's external HTTP requests should also be monitored for potential vulnerabilities in the remote services it communicates with.
While the plugin has a clean historical record, which is a significant strength, the identified unsanitized taint flows suggest that continuous vigilance and thorough code review are still necessary. The overall risk is moderate, leaning towards lower due to the lack of historical issues and strong implementation of core security practices. The key recommendation is to investigate and sanitize the identified taint flows to eliminate any potential risk, even if they are not currently critical. Monitoring the security of external dependencies is also prudent. The plugin benefits from a well-defined attack surface and robust internal security mechanisms, but the identified taint flows prevent a completely clean bill of health.
Key Concerns
- Taint flows with unsanitized paths (3)
BORICA Payments by BORICA AD Security Vulnerabilities
BORICA Payments by BORICA AD Release Timeline
BORICA Payments by BORICA AD Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BORICA Payments by BORICA AD Attack Surface
AJAX Handlers 24
WordPress Hooks 33
Maintenance & Trust
BORICA Payments by BORICA AD Maintenance & Trust
Maintenance Signals
Community Trust
BORICA Payments by BORICA AD Alternatives
Up2pay e-Transactions WooCommerce Payment Gateway
e-transactions-wc
This plugin is a Up2pay e-Transactions payment gateway for WooCommerce 4.x
HyperPay Payments
hyperpay-gateways
Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.
Paybox WooCommerce Payment Gateway
paybox-woocommerce-gateway
This plugin is a Paybox payment gateway for WooCommerce 4.x
KueskiPay Gateway
kueskipay-gateway
Add Kueski gateway to buy now and pay later on your store.
Monnify Official
monnify-official
Monnify Official WooCommerce Payment Gateway plugin provides a seamless payment experience for your customers on your WordPress website.
BORICA Payments by BORICA AD Developer Profile
1 plugin · 500 total installs
How We Detect BORICA Payments by BORICA AD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/borica-payments/css/borica-payment-gateway.css/wp-content/plugins/borica-payments/js/borica-payment-gateway.js/wp-content/plugins/borica-payments/js/borica-payment-gateway-admin.js/wp-content/plugins/borica-payments/js/borica-payment-gateway.js/wp-content/plugins/borica-payments/js/borica-payment-gateway-admin.jsborica-payments/css/borica-payment-gateway.css?ver=borica-payments/js/borica-payment-gateway.js?ver=borica-payments/js/borica-payment-gateway-admin.js?ver=HTML / DOM Fingerprints
borica_payment_gateway_params