CampTix RazorPay Payment Gateway Security & Risk Analysis

wordpress.org/plugins/campt-razorpay-payment-gateway

Razorpay Gateway Add-on for Camptix.

0 active installs v0.4 PHP + WP 4.2+ Updated Dec 22, 2017
camptixgatewayrazorpay
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CampTix RazorPay Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

CampTix RazorPay Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'campt-razorpay-payment-gateway' plugin version 0.4 exhibits a generally good security posture based on static analysis, with no directly exploitable attack surface points like unprotected AJAX handlers or REST API routes. The absence of dangerous functions, file operations, and external HTTP requests is also positive. The plugin uses prepared statements for all its SQL queries, which is a strong security practice.

However, a significant concern arises from the taint analysis, which identified one flow with an unsanitized path and rated it as high severity. This indicates a potential vulnerability where user-supplied data might be processed without adequate sanitization, leading to unexpected or malicious behavior. The lack of nonce and capability checks across all entry points (though the entry point count is zero) is also a weakness, as it means if any new entry points are inadvertently introduced or if the current analysis is incomplete, they would lack critical security measures.

The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of responsible development or limited exposure to sophisticated attacks. Despite the concerning taint flow, the overall lack of historical vulnerabilities and the strong practices in SQL querying and output escaping paint a picture of a plugin with potential weaknesses but a generally responsible development approach.

Key Concerns

  • High severity unsanitized taint flow
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

CampTix RazorPay Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CampTix RazorPay Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

88% escaped8 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-camptix-payment-method-razorpay> (inc\class-camptix-payment-method-razorpay.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CampTix RazorPay Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedcamptix-razorpay.php:65
actionplugins_loadedcamptix-razorpay.php:66
filtercamptix_currenciescamptix-razorpay.php:90
actioncamptix_load_addonscamptix-razorpay.php:91
actiontemplate_redirectinc\class-camptix-payment-method-razorpay.php:92
actioncamptix_attendee_form_additional_infoinc\class-camptix-payment-method-razorpay.php:93
filtercamptix_register_order_summary_headerinc\class-camptix-payment-method-razorpay.php:94
filtercamptix_form_register_complete_attendee_objectinc\class-camptix-payment-method-razorpay.php:95
actioncamptix_checkout_update_post_metainc\class-camptix-payment-method-razorpay.php:96
filtercamptix_metabox_attendee_info_additional_rowsinc\class-camptix-payment-method-razorpay.php:97
Maintenance & Trust

CampTix RazorPay Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedDec 22, 2017
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

CampTix RazorPay Payment Gateway Developer Profile

Arvind Singh

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CampTix RazorPay Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/camptix-razorpay-payment-gateway/inc/lib/razorpay-php/Razorpay.php/wp-content/plugins/camptix-razorpay-payment-gateway/inc/class-camptix-payment-method-razorpay.php

HTML / DOM Fingerprints

CSS Classes
tix-row-phonetix-requiredtix-lefttix-righttix-required-star
Data Attributes
name="tix_attendee_infovalue="Rs.
FAQ

Frequently Asked Questions about CampTix RazorPay Payment Gateway