
Duzz Portal – Stripe Custom Customer Payments Security & Risk Analysis
wordpress.org/plugins/duzz-custom-portalInstantly connect with your customers and keep the conversation going with Duzz Custom Portal.
Is Duzz Portal – Stripe Custom Customer Payments Safe to Use in 2026?
Generally Safe
Score 92/100Duzz Portal – Stripe Custom Customer Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The duzz-custom-portal plugin v1.2.2 exhibits a generally good security posture, with robust application of nonce and capability checks, and a high percentage of properly escaped output. The absence of any recorded historical vulnerabilities further strengthens this impression. However, a significant concern arises from the static analysis of SQL queries, where 100% of queries are not using prepared statements. This presents a notable risk for SQL injection vulnerabilities, especially if any of the input parameters used in these queries originate from user-controlled sources. While the taint analysis did not reveal critical or high-severity unsanitized flows, the presence of two flows with unsanitized paths warrants careful review to ensure these do not lead to exploitable weaknesses, particularly in conjunction with the un-prepared SQL queries.
Despite the strong adherence to WordPress security best practices in many areas, the unmitigated risk associated with raw SQL queries is the primary weakness. The plugin's history of zero vulnerabilities could indicate either a very well-written codebase historically or simply a lack of targeted discovery, making the identified code signals more critical. In conclusion, while the plugin demonstrates many positive security attributes, the lack of prepared statements for SQL queries introduces a significant potential for exploitation that needs immediate attention.
Key Concerns
- SQL queries without prepared statements
- Taint flows with unsanitized paths (2)
Duzz Portal – Stripe Custom Customer Payments Security Vulnerabilities
Duzz Portal – Stripe Custom Customer Payments Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Duzz Portal – Stripe Custom Customer Payments Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 94
Maintenance & Trust
Duzz Portal – Stripe Custom Customer Payments Maintenance & Trust
Maintenance Signals
Community Trust
Duzz Portal – Stripe Custom Customer Payments Alternatives
n8n Chat Widget
n8n-chat-widget
Adds a customizable n8n chat widget to your website frontend. It allows visitors to interact with n8n chat workflows directly from your website throug …
Chat Floating Button BY XD
chat-floating-button-by-xd
Floating button for chatting with your visitors via WhatsApp.
China Payments Plugin | Accept WeChat Pay, Alipay & UnionPay | Chinese Checkout Optimization
wp-stripe-global-payments
Accept WeChat Pay, Alipay & UnionPay via Stripe. Chinese checkout optimization with localization, multi-currency display & CNY conversion for …
Richpanel – Customer Support Helpdesk & Chat
richpanel-for-woocommerce
Free Live Chat & Help desk for WooCommerce. Integrate in 2 mins.
Dante AI
dante-ai
Add a helpful AI chatbot to your WordPress site in minutes - boost engagement, answer questions, and turn more visitors into customers.
Duzz Portal – Stripe Custom Customer Payments Developer Profile
1 plugin · 10 total installs
How We Detect Duzz Portal – Stripe Custom Customer Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duzz-custom-portal/assets/css/duzz-custom-portal.css/wp-content/plugins/duzz-custom-portal/assets/js/duzz-custom-portal.js/wp-content/plugins/duzz-custom-portal/assets/css/duzz-admin.css/wp-content/plugins/duzz-custom-portal/vendor/autoload.phpduzz-custom-portal/assets/css/duzz-custom-portal.css?ver=duzz-custom-portal/assets/js/duzz-custom-portal.js?ver=duzz-custom-portal/assets/css/duzz-admin.css?ver=HTML / DOM Fingerprints
duzz-acf-field-groupduzz-field-settings<!-- The Duzz Custom Portal plugin recommends the following plugin: %1$s. --><!-- The Duzz Custom Portal plugin recommends the following plugins: %1$s. -->data-noncedata-ajaxurlduzzACFData