
DC Nagad Payment Security & Risk Analysis
wordpress.org/plugins/dc-nagadYou can easily pay via Nagad.
Is DC Nagad Payment Safe to Use in 2026?
Generally Safe
Score 85/100DC Nagad Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dc-nagad' v1.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has no known vulnerabilities (CVEs) and a clean history, which is a significant positive indicator. The static analysis reveals a small attack surface with only one AJAX handler, and importantly, it appears to be protected by authentication. The code signals also indicate good practices, with a high percentage of SQL queries using prepared statements and output escaping. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, a few areas warrant attention. While the AJAX handler is protected, the lack of explicit capability checks on it could be a concern if the authentication mechanism is bypassed or if the authenticated user has overly broad permissions. The presence of external HTTP requests, though only two, introduces a dependency on external services, which could be a vector for supply chain attacks or denial-of-service if those services become unavailable. The taint analysis showing zero flows is excellent, suggesting no immediately apparent data corruption or command execution vulnerabilities in the analyzed code paths.
Overall, the plugin appears to be developed with security in mind, demonstrated by its clean vulnerability history and robust code practices. The limited attack surface and strong adherence to prepared statements and output escaping are commendable. The primary areas for potential improvement lie in ensuring granular capability checks on its entry points and being mindful of the risks associated with external HTTP requests. The absence of any recorded vulnerabilities over time is a strong indicator of a well-maintained and secure plugin.
Key Concerns
- No capability checks on AJAX handler
- External HTTP requests present
DC Nagad Payment Security Vulnerabilities
DC Nagad Payment Code Analysis
SQL Query Safety
Output Escaping
DC Nagad Payment Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
DC Nagad Payment Maintenance & Trust
Maintenance Signals
Community Trust
DC Nagad Payment Alternatives
Flying Pay
flying-pay-gateway
A seamless and secure payment gateway integration for WooCommerce featuring Mobile Banking, 4 Major Banks, and Crypto support with an interactive UI.
DC EDD bKash Payment
dc-edd-bkash-payment
bKash payment gateway for Easy Digital Downloads.
Deshi Pay bKash, Rocket, Nagad
deshi-pay
A professional and modern manual payment gateway for WooCommerce supporting bKash, Nagad, and Rocket with a sleek UI and easy copy features.
bKash & Mobile Payment – Fast Checkout, Partial Payment & Buy Now Button
bangla-press
bKash, Nagad, Rocket, and Upay payments for WooCommerce with partial payments,Buy Now Button, and complete control over checkout options.
Nagad Payment Gateway
nagad-payment-gateway
This is official Nagad Payment Gateway plugin for woocommerce websites.
DC Nagad Payment Developer Profile
4 plugins · 1K total installs
How We Detect DC Nagad Payment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dc-nagad/assets/css/backend.css/wp-content/plugins/dc-nagad/assets/css/frontend.css/wp-content/plugins/dc-nagad/assets/js/backend.js/wp-content/plugins/dc-nagad/assets/js/frontend.js/wp-content/plugins/dc-nagad/assets/js/backend.js/wp-content/plugins/dc-nagad/assets/js/frontend.jsHTML / DOM Fingerprints
dc-nagad-admin-settingsCopyright (c) 2020 Kapil Paul (email: kapilpaul007@gmail.com). All rights reserved.This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+1 moredata-gateway-urldc_nagad_ajax_object/wp-json/dc-nagad/v1/process-payment