
Conekta Payment Gateway Security & Risk Analysis
wordpress.org/plugins/conekta-payment-gatewayWooCommerce Payment Gateway for Conekta.io This bundles functionality to process credit cards and cash payments securely as well as send email notific …
Is Conekta Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100Conekta Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The conekta-payment-gateway plugin version 5.4.8 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and the absence of known critical or high-severity vulnerabilities in its history. This suggests a developer aware of common pitfalls. However, the static analysis reveals significant concerns, particularly in the handling of entry points. The presence of one REST API route without permission callbacks is a major weakness, as it exposes a potentially unprotected endpoint to unauthorized access. Furthermore, the lack of nonce checks and capability checks on any of its entry points, combined with a relatively high percentage (77%) of properly escaped outputs, indicates a potential for certain types of attacks if the unprotected REST API route can be manipulated. The bundled Guzzle library should be monitored for known vulnerabilities, although no specific issues are indicated in the provided data.
Overall, while the plugin has a clean vulnerability history and good SQL hygiene, the unprotected REST API endpoint represents a critical security risk. The absence of authentication and authorization checks on this entry point makes it a prime target for various web attacks. The other analyzed areas like AJAX handlers, shortcodes, and cron events being absent or protected are positive, but they do not mitigate the risk posed by the exposed REST API. A balanced conclusion would be that the plugin has potential for good security, but this specific version has a critical flaw that requires immediate attention.
Key Concerns
- REST API routes without permission callbacks
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Output escaping below 100%
Conekta Payment Gateway Security Vulnerabilities
Conekta Payment Gateway Code Analysis
Bundled Libraries
Output Escaping
Conekta Payment Gateway Attack Surface
REST API Routes 1
WordPress Hooks 44
Maintenance & Trust
Conekta Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Conekta Payment Gateway Alternatives
OXXO PAY powered by Spin
digitalfemsa-payment-gateway
WooCommerce Payment Gateway for DigitalFemsa.io: Securely process cash payments and send email notifications for successful purchases.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Cashfree for WooCommerce
cashfree
Official Cashfree Payment Gateway plugin for WooCommerce.
Knit Pay – Cashfree, Instamojo, Razorpay, Paypal and more
knit-pay
Seamlessly integrates 500+ payment gateways, including Cashfree, Instamojo, PayPal, Razorpay, and SSLCommerz, with over 100 WordPress plugins.
CashBill.pl – Płatności WooCommerce
cashbill-payment-method
Dedykowane rozwiązanie integrujące najpopularniejsze metody płatności. Dzięki tej wtyczce możesz w atrakcyjny sposób prezentować siatkę z logotypami b …
Conekta Payment Gateway Developer Profile
1 plugin · 2K total installs
How We Detect Conekta Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/conekta-payment-gateway/resources/js/frontend/classic-translations.js/wp-content/plugins/conekta-payment-gateway/resources/js/frontend/classic-checkout.jshttps://pay.conekta.com/v1.0/js/conekta-checkout.min.jsHTML / DOM Fingerprints
conekta_settings