
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/e-nkap-woocommerce-gatewayA secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or website
Is SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The e-nkap-woocommerce-gateway plugin version 1.0.8 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices in output escaping, with all 47 detected outputs being properly escaped. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a potentially stable and well-maintained codebase. The absence of dangerous functions, file operations, and external HTTP requests also contributes to a reduced attack surface in those specific areas.
However, there are significant concerns regarding the plugin's entry points. Out of 3 total entry points, 2 are unprotected. Specifically, there are 2 REST API routes that lack permission callbacks, exposing them to unauthorized access. While the static analysis did not reveal any dangerous functions or critical taint flows, the presence of unprotected entry points is a substantial risk. The static analysis also found 8 SQL queries, with 50% not using prepared statements, which could potentially lead to SQL injection vulnerabilities if not handled carefully.
In conclusion, while the plugin has strong output handling and a clean vulnerability history, the lack of proper authentication and authorization on its REST API routes represents a critical security weakness. The SQL query practices also warrant attention. Addressing these unprotected entry points and reinforcing SQL query security should be the primary focus for improving the plugin's overall security.
Key Concerns
- Unprotected REST API routes
- SQL queries without prepared statements
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Security Vulnerabilities
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Release Timeline
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 13
Maintenance & Trust
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Alternatives
Gateway Payougo Checkout
gateway-payougo-checkout
With Payougo, easyly accept secure Orange Money & MTN Mobile Money payments from Cameroon subscribers on your web store.
SoleasPay payment gateway for WooCommerce
soleaspay-payment-gateway-for-woocommerce
SoleasPay - Payment gateway for WooCommerce
Campay Woocommerce Payment Gateway
campay-api
CamPay is a Fintech service of the company TAKWID
UnitechPay – Wave & Orange Money Payments
unitechpay-paiements-mobile-money
Solution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !
My-CoolPay – Payment gateway for WooCommerce
my-coolpay-payment-gateway-for-woocommerce
The best modern and secure payment plugin for WooCommerce in Cameroon accepting Orange Money, MTN Mobile Money, VISA, MasterCard and My-CoolPay Wallet
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Developer Profile
4 plugins · 290 total installs
How We Detect SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/e-nkap-woocommerce-gateway/includes/assets/css/admin-style.css