
CamPay Shortcode Payment Gateway Security & Risk Analysis
wordpress.org/plugins/campay-shortcode-payment-gatewayCamPay is a Fintech service of the company TAKWID
Is CamPay Shortcode Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100CamPay Shortcode Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "campay-shortcode-payment-gateway" plugin version 1.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and maintaining a high percentage of properly escaped output, mitigating common data leakage and injection risks. The absence of known CVEs and bundled libraries further contributes to a relatively stable history. However, significant concerns arise from its attack surface and authentication mechanisms. With three identified entry points, two of which lack any authentication or capability checks, the plugin exposes itself to potential unauthorized access and execution of sensitive functions. The presence of the 'assert' dangerous function, although not explicitly linked to a taint flow in this analysis, warrants caution as it can be misused in certain contexts. The complete lack of nonce checks on AJAX handlers is a critical oversight that could allow for Cross-Site Request Forgery (CSRF) attacks.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function 'assert' found
- No nonce checks on AJAX handlers
- Entry points without auth checks
CamPay Shortcode Payment Gateway Security Vulnerabilities
CamPay Shortcode Payment Gateway Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
CamPay Shortcode Payment Gateway Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
CamPay Shortcode Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
CamPay Shortcode Payment Gateway Alternatives
Campay Woocommerce Payment Gateway
campay-api
CamPay is a Fintech service of the company TAKWID
CamPay Give Donation Payment Gateway
campay-give
CamPay is a Fintech service of the company TAKWID
Finachub Lipa na Mpesa Checkout for WooCommerce
finachub-checkout-for-m-pesa
Accept M-Pesa STK Push payments in WooCommerce. A simple and reliable way to integrate Kenya's most popular payment method.
UnitechPay – Wave & Orange Money Payments
unitechpay-paiements-mobile-money
Solution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !
Direct Payments WP
direct-payments-wp
Direct Payments WP lets you easily accept payments via bank transfers, mobile money, and P2P platforms on your WordPress website.
CamPay Shortcode Payment Gateway Developer Profile
3 plugins · 220 total installs
How We Detect CamPay Shortcode Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.