
CubeWP Wallet Security & Risk Analysis
wordpress.org/plugins/cubewp-walletA Digital wallet plugin for websites that allows customers to make payments using their stored funds.
Is CubeWP Wallet Safe to Use in 2026?
Generally Safe
Score 100/100CubeWP Wallet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cubewp-wallet v1.0.5 plugin demonstrates a generally strong security posture based on the provided static analysis. It exhibits good practices by avoiding dangerous functions, file operations, and external HTTP requests. The high percentage of properly escaped output (93%) and the presence of nonce checks (14) are positive indicators. Furthermore, the absence of any known vulnerabilities (CVEs) and critical or high-severity taint flows suggests a well-developed and maintained codebase.
However, there are a few areas that warrant attention. The plugin has a significant number of SQL queries (21), with a substantial portion (57%) not using prepared statements. While not explicitly identified as a vulnerability in the taint analysis, raw SQL queries can be a vector for SQL injection if not handled with extreme care, especially as the number increases.
In conclusion, cubewp-wallet v1.0.5 appears to be a secure plugin with a promising history and strong adherence to many security best practices. The primary concern lies in the handling of its SQL queries, where a greater reliance on prepared statements would further enhance its security. The lack of capability checks on the identified entry point (shortcode) is also a minor concern, though its impact depends on the functionality it provides.
Key Concerns
- SQL queries without prepared statements
- No capability checks on shortcode
CubeWP Wallet Security Vulnerabilities
CubeWP Wallet Release Timeline
CubeWP Wallet Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CubeWP Wallet Attack Surface
Shortcodes 1
WordPress Hooks 25
Maintenance & Trust
CubeWP Wallet Maintenance & Trust
Maintenance Signals
Community Trust
CubeWP Wallet Alternatives
Nexi XPay
cartasi-x-pay
XPay is the payment gateway provided by Nexi, a leading group in Italy with the goal of shaping the future of digital payments.
Instamojo for WooCommerce
woo-instamojo
Sell & collect payments instantly for almost anything -- directly from your WordPress website.
Up2pay e-Transactions WooCommerce Payment Gateway
e-transactions-wc
This plugin is a Up2pay e-Transactions payment gateway for WooCommerce 4.x
HyperPay Payments
hyperpay-gateways
Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.
PAYDUNYA WOOCOMMERCE PAR
paydunya-woocommerce-payment-gateway
PAYDUNYA Woocommerce Payment Gateway allows you to accept payment on your Woocommerce store, PAYDUNYA supports Mobile Wallets Method Payment and Bank …
CubeWP Wallet Developer Profile
3 plugins · 8K total installs
How We Detect CubeWP Wallet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cubewp-wallet/cube/assets/css/cubewp-wallet-admin.css/wp-content/plugins/cubewp-wallet/cube/assets/css/cubewp-wallet-user.css/wp-content/plugins/cubewp-wallet/cube/assets/js/cubewp-wallet-admin.js/wp-content/plugins/cubewp-wallet/cube/assets/js/cubewp-wallet-user.js/wp-content/plugins/cubewp-wallet/cube/assets/js/cubewp-wallet-admin.js/wp-content/plugins/cubewp-wallet/cube/assets/js/cubewp-wallet-user.jscubewp-wallet/cube/assets/css/cubewp-wallet-admin.css?ver=cubewp-wallet/cube/assets/css/cubewp-wallet-user.css?ver=cubewp-wallet/cube/assets/js/cubewp-wallet-admin.js?ver=cubewp-wallet/cube/assets/js/cubewp-wallet-user.js?ver=HTML / DOM Fingerprints
cubewp-wallet-admincubewp-wallet-userdata-cubewp-wallet-user-idcubewp_wallet_admin_object[cubewp_wallet]