Chinese WeChat Pay for American merchants(微信支付美国版) Security & Risk Analysis

wordpress.org/plugins/chinese-wechat-pay-for-american-merchants

Allow American merchants to integrate WeChat Pay with WordPress sites. Clients pay in Chinese Yuan and U.S. merchants receive money in US dollars ($US …

10 active installs v1.6.5 PHP 5.6+ WP 4.3+ Updated Feb 26, 2023
chinese-payment%e7%be%8e%e5%9b%bdnoveltypaywechat-pay%e5%be%ae%e4%bf%a1%e6%94%af%e4%bb%98
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Chinese WeChat Pay for American merchants(微信支付美国版) Safe to Use in 2026?

Generally Safe

Score 85/100

Chinese WeChat Pay for American merchants(微信支付美国版) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "chinese-wechat-pay-for-american-merchants" v1.6.5 plugin exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerability history, significant concerns arise from its static analysis results. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a substantial attack surface, as unauthenticated users could potentially interact with these endpoints, leading to unintended actions or information disclosure.

The taint analysis revealed one flow with an unsanitized path, although it was not classified as critical or high severity. This suggests a potential for subtle vulnerabilities if inputs are not properly validated and sanitized before being used. The lack of nonce checks on the AJAX handlers further exacerbates the risk, as it allows for Cross-Site Request Forgery (CSRF) attacks. The absence of capability checks on these entry points also means that any authenticated user, regardless of their role, could trigger these functions.

Overall, the plugin's strengths lie in its SQL handling and lack of historical vulnerabilities. However, the unprotected AJAX endpoints and the identified unsanitized data flow are significant weaknesses that require immediate attention. The potential for CSRF and unauthorized access to functionality necessitates a cautious approach to using this plugin until these issues are addressed.

Key Concerns

  • Unprotected AJAX handlers
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
  • Flow with unsanitized path (non-critical)
Vulnerabilities
None known

Chinese WeChat Pay for American merchants(微信支付美国版) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chinese WeChat Pay for American merchants(微信支付美国版) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped19 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-wc-wechatpay-by-novelty-payment> (class-wc-wechatpay-by-novelty-payment.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Chinese WeChat Pay for American merchants(微信支付美国版) Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_get_order_status_wechatbynoveltynovelty_wechatpay_init.php:38
noprivwp_ajax_get_order_status_wechatbynoveltynovelty_wechatpay_init.php:39
WordPress Hooks 4
actionwoocommerce_update_options_payment_gatewaysclass-wc-wechatpay-by-novelty-payment.php:43
filterwoocommerce_payment_gatewaysnovelty_wechatpay_init.php:36
actionwp_enqueue_scriptsnovelty_wechatpay_init.php:41
actionplugins_loadednovelty_wechatpay_init.php:46
Maintenance & Trust

Chinese WeChat Pay for American merchants(微信支付美国版) Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 26, 2023
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Chinese WeChat Pay for American merchants(微信支付美国版) Developer Profile

Novelty Payments

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chinese WeChat Pay for American merchants(微信支付美国版)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chinese-wechat-pay-for-american-merchants/images/logo.png

HTML / DOM Fingerprints

Data Attributes
data-plugin-name="chinese-wechat-pay-for-american-merchants"
JS Globals
window.wechatpay_globalvar wechatpay_global
REST Endpoints
/wp-json/wc-wechatpay-by-novelty-payment-gateway/v1/order-status
FAQ

Frequently Asked Questions about Chinese WeChat Pay for American merchants(微信支付美国版)