
Direct Payments WP Security & Risk Analysis
wordpress.org/plugins/direct-payments-wpDirect Payments WP lets you easily accept payments via bank transfers, mobile money, and P2P platforms on your WordPress website.
Is Direct Payments WP Safe to Use in 2026?
Use With Caution
Score 56/100Direct Payments WP has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The 'direct-payments-wp' plugin v1.3.2 presents a mixed security posture. While it demonstrates good practices in areas like prepared SQL statements (98%) and output escaping (96%), significant concerns arise from its attack surface and vulnerability history.
The static analysis reveals 64 AJAX handlers, with a worrying 4 lacking authentication checks. This directly translates to potential unauthorized access to plugin functionalities. Furthermore, taint analysis identified 2 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if not properly addressed. The presence of 'unserialize' is also a known risk factor, especially when handling user-supplied data, though its specific usage and impact are not detailed in the provided data.
The plugin's vulnerability history, with 2 known medium-severity CVEs that remain unpatched, is a critical concern. The recurring themes of 'Exposure of Sensitive Information to an Unauthorized Actor' and 'Missing Authorization' align with the static analysis findings, suggesting a pattern of authorization and data leakage issues. The recent unpatched CVEs, even at medium severity, necessitate immediate attention to prevent exploitation. While the plugin has strengths in general coding hygiene, the specific areas of unauthenticated entry points and unpatched vulnerabilities significantly elevate its risk profile.
Key Concerns
- Unpatched CVEs (2 medium)
- High severity taint flows (2)
- Unprotected AJAX handlers (4)
- Dangerous function: unserialize
- Vulnerability history: Missing Authorization
- Vulnerability history: Exposure of Sensitive Information
Direct Payments WP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Direct Payments WP <= 1.3.0 - Authenticated (Subscriber+) Sensitive Information Exposure
Direct Payments WP <= 1.3.0 - Missing Authorization
Direct Payments WP Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Direct Payments WP Attack Surface
AJAX Handlers 64
Shortcodes 1
WordPress Hooks 48
Maintenance & Trust
Direct Payments WP Maintenance & Trust
Maintenance Signals
Community Trust
Direct Payments WP Alternatives
Mollie Forms
mollie-forms
Create registration forms with payment methods of Mollie. One-time and recurring payments are possible.
Payment Forms for Paystack
payment-forms-for-paystack
Create forms with multiple input fields and have your users pay before submission. Form submission results are available on your dashboard.
Checkout with Zelle on Woocommerce
wc-zelle
Receive Zelle payments on your website with WooCommerce + Zelle
Checkout Gateway for IRIS
checkout-gateway-iris
Unofficial IRIS checkout payment gateway for WooCommerce. Accept payments via IRIS and manage order statuses efficiently.
Direct Payments for WooCommerce – Bank Transfer, Mobile Money, Crypto and Peer-to-Peer (P2P) Payments
direct-payments-for-woocommerce
Direct Payments for WooCommerce allows your store to accept instant payments via bank transfers, mobile money, crypto and popular P2P platforms global …
Direct Payments WP Developer Profile
5 plugins · 850 total installs
How We Detect Direct Payments WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/direct-payments-wp/assets/js/hide-view-form.js/wp-content/plugins/direct-payments-wp/select.css/wp-content/plugins/direct-payments-wp/select2.min.js/wp-content/plugins/direct-payments-wp/admin/forms/form-manager.jsadmin/forms/form-manager.jsassets/js/hide-view-form.jsselect2.min.jsselect.cssdirect-payments-wp/admin/forms/form-manager.js?ver=1.3.2direct-payments-wp/assets/js/hide-view-form.js?ver=1.3.2direct-payments-wp/select2.min.js?ver=1.3.2direct-payments-wp/select.css?ver=1.3.2HTML / DOM Fingerprints
custom-plugin-select2tumaz_form_management