
DC EDD bKash Payment Security & Risk Analysis
wordpress.org/plugins/dc-edd-bkash-paymentbKash payment gateway for Easy Digital Downloads.
Is DC EDD bKash Payment Safe to Use in 2026?
Generally Safe
Score 85/100DC EDD bKash Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dc-edd-bkash-payment" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL injection risks due to a high percentage of prepared statements and the robust output escaping (94%) are positive indicators. Furthermore, the lack of file operations, external HTTP requests, and critical or high-severity taint flows suggest careful coding practices. The plugin also demonstrates awareness of security best practices by including a sufficient number of nonce checks.
However, a notable concern is the complete absence of capability checks for its two AJAX entry points. While the static analysis reports no unprotected AJAX handlers, this likely refers to the presence of nonces. Without proper capability checks, an attacker might be able to trigger these AJAX actions if they can bypass or spoof the nonce, especially if the actions themselves perform sensitive operations. The vulnerability history being entirely clear is a positive sign, indicating a history of secure development or a lack of past exploitation. The plugin's strengths lie in its sanitization and input handling, but the lack of explicit authorization checks on its AJAX endpoints is a weakness that needs addressing.
Key Concerns
- Missing capability checks on AJAX handlers
DC EDD bKash Payment Security Vulnerabilities
DC EDD bKash Payment Code Analysis
SQL Query Safety
Output Escaping
DC EDD bKash Payment Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
DC EDD bKash Payment Maintenance & Trust
Maintenance Signals
Community Trust
DC EDD bKash Payment Alternatives
Flying Pay
flying-pay-gateway
A seamless and secure payment gateway integration for WooCommerce featuring Mobile Banking, 4 Major Banks, and Crypto support with an interactive UI.
DC Nagad Payment
dc-nagad
You can easily pay via Nagad.
Deshi Pay bKash, Rocket, Nagad
deshi-pay
A professional and modern manual payment gateway for WooCommerce supporting bKash, Nagad, and Rocket with a sleek UI and easy copy features.
bKash & Mobile Payment – Fast Checkout, Partial Payment & Buy Now Button
bangla-press
bKash, Nagad, Rocket, and Upay payments for WooCommerce with partial payments,Buy Now Button, and complete control over checkout options.
Bangladeshi Taka in WooCommerce
bangladeshi-taka-in-woocommerce
This plugin adds Bangladeshi Taka (BDT) to WooCommerce powered store
DC EDD bKash Payment Developer Profile
4 plugins · 1K total installs
How We Detect DC EDD bKash Payment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dc-edd-bkash-payment/assets/css/admin.css/wp-content/plugins/dc-edd-bkash-payment/assets/js/admin.js/wp-content/plugins/dc-edd-bkash-payment/assets/js/admin.jsdc-edd-bkash-payment/assets/css/admin.css?ver=dc-edd-bkash-payment/assets/js/admin.js?ver=HTML / DOM Fingerprints
dc-edd-bkash-admin-wrapCopyright (c) 2020 Kapil Paul (email: kapilpaul007@gmail.com). All rights reserved.Released under the GPL licenseThis is an add-on for WordPress**********************************************************************+45 moredata-bkash-payment-idwindow.dc_edd_bkash_params