
CodeCareBD – Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/codecarebd-bkash-nagad-rocket-payoneer-gatewayCodeCareBD - Payment Gateway plugin integrates bKash, Nagad, Rocket, and Payoneer Payment Gateways with WooCommerce.
Is CodeCareBD – Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100CodeCareBD – Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, "codecarebd-bkash-nagad-rocket-payoneer-gateway" v1.0, exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries executed without prepared statements, and a significant majority of properly escaped output are positive indicators. Furthermore, the plugin demonstrates good practice by including a nonce check and having no known historical vulnerabilities, suggesting a commitment to security over time.
However, a notable concern arises from the taint analysis, which identified one flow with unsanitized paths. While no critical or high severity issues were flagged in the taint analysis, an unsanitized path represents a potential entry point for malicious data to be processed without proper validation, which could lead to various vulnerabilities depending on how that data is subsequently used. The lack of capability checks on the identified entry points (even though the total number is zero) means that if any entry points were to be introduced in future versions, they might not be adequately protected against unauthorized access.
In conclusion, the plugin's current version is relatively secure due to its development practices and clean vulnerability history. The primary area for improvement lies in rigorously addressing the identified unsanitized path flow to eliminate potential risks. Future development should also prioritize implementing capability checks for any new entry points to maintain a robust security foundation.
Key Concerns
- Flow with unsanitized paths
- Lack of capability checks on entry points
CodeCareBD – Payment Gateway for WooCommerce Security Vulnerabilities
CodeCareBD – Payment Gateway for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
CodeCareBD – Payment Gateway for WooCommerce Attack Surface
WordPress Hooks 27
Maintenance & Trust
CodeCareBD – Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CodeCareBD – Payment Gateway for WooCommerce Alternatives
SoftTech-IT bKash, Rocket, Nagad
bkash
Easy to use bKash , Rocket and Nagad Payment Gateway for Woocommerce
Bangladeshi Payments Mobile – QR Code & Transaction Reports
bangladeshi-payments-mobile
Accept Mobile Payments in Bangladesh – WooCommerce Gateway for bKash, Nagad, Rocket & Upay with QR Code & Transaction Reports.
UddoktaPay
uddoktapay-gateway
UddoktaPay Plugin for WooCommerce.
bKash & Mobile Payment – Fast Checkout, Partial Payment & Buy Now Button
bangla-press
bKash, Nagad, Rocket, and Upay payments for WooCommerce with partial payments,Buy Now Button, and complete control over checkout options.
Flying Pay
flying-pay-gateway
A seamless and secure payment gateway integration for WooCommerce featuring Mobile Banking, 4 Major Banks, and Crypto support with an interactive UI.
CodeCareBD – Payment Gateway for WooCommerce Developer Profile
1 plugin · 300 total installs
How We Detect CodeCareBD – Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/css/checkout.css/wp-content/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/js/checkout.js/wp-content/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/js/checkout.jscodecarebd-bkash-nagad-rocket-payoneer-gateway/assets/css/checkout.css?ver=codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/js/checkout.js?ver=HTML / DOM Fingerprints
<!-- Begin cc-payment-gateway-domain --><!-- End cc-payment-gateway-domain -->data-gateway-id="ccd_bkash"data-gateway-id="ccd_nagad"data-gateway-id="ccd_rocket"data-gateway-id="ccd_payoneer"