
Campay Woocommerce Payment Gateway Security & Risk Analysis
wordpress.org/plugins/campay-apiCamPay is a Fintech service of the company TAKWID
Is Campay Woocommerce Payment Gateway Safe to Use in 2026?
Generally Safe
Score 99/100Campay Woocommerce Payment Gateway has a strong security track record. Known vulnerabilities have been patched promptly.
The "campay-api" v1.2.3 plugin exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and has no known unpatched vulnerabilities, several areas raise significant concerns. The complete absence of nonce checks and capability checks across all identified entry points (though currently zero) is a major red flag. This lack of proper authorization and protection against CSRF attacks means that if any entry points are introduced or discovered, they would be immediately exploitable. The presence of the `assert` function, a dangerous function that can be misused for code execution if not handled with extreme care, is also a point of concern, especially in conjunction with the lack of robust authentication checks. The vulnerability history shows a past medium-severity vulnerability related to authorization bypass through a user-controlled key, which, while currently patched, suggests a pattern of potential weaknesses in how user-supplied data or keys are handled, necessitating ongoing vigilance. In conclusion, while the plugin avoids common pitfalls like raw SQL queries and unpatched CVEs, the fundamental absence of authentication and authorization mechanisms on its attack surface, coupled with the use of a dangerous function, presents a substantial risk if the attack surface expands or is discovered.
Key Concerns
- No nonce checks present
- No capability checks present
- Dangerous function 'assert' present
- Low percentage of properly escaped outputs (66%)
- Past medium severity vulnerability (Authorization Bypass)
Campay Woocommerce Payment Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Campay Woocommerce Payment Gateway <= 1.2.2 - Unauthenticated Payment Bypass
Campay Woocommerce Payment Gateway Code Analysis
Dangerous Functions Found
Output Escaping
Campay Woocommerce Payment Gateway Attack Surface
WordPress Hooks 9
Maintenance & Trust
Campay Woocommerce Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Campay Woocommerce Payment Gateway Alternatives
CamPay Give Donation Payment Gateway
campay-give
CamPay is a Fintech service of the company TAKWID
CamPay Shortcode Payment Gateway
campay-shortcode-payment-gateway
CamPay is a Fintech service of the company TAKWID
Finachub Lipa na Mpesa Checkout for WooCommerce
finachub-checkout-for-m-pesa
Accept M-Pesa STK Push payments in WooCommerce. A simple and reliable way to integrate Kenya's most popular payment method.
UnitechPay – Wave & Orange Money Payments
unitechpay-paiements-mobile-money
Solution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce
e-nkap-woocommerce-gateway
A secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or website
Campay Woocommerce Payment Gateway Developer Profile
3 plugins · 220 total installs
How We Detect Campay Woocommerce Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/campay-api/assets/img/logo-campay-momo.png/wp-content/plugins/campay-api/assets/js/campay_checkout.jscampay-api/assets/js/campay_checkout.js?ver=HTML / DOM Fingerprints
<!-- CamPay Payment Processing Modal --><!-- CamPay Checkout Form Submit -->data-campay-usernamedata-campay-passworddata-campay-webhook-urldata-campay-webhook-keydata-campay-testmodedata-campay-dollar-activated+4 morewindow.campay_checkout_params/wp-json/campay/v1/webhook