SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/e-nkap-woocommerce-gateway

A secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or website

30 active installs v1.0.8 PHP 7.3+ WP 4.8+ Updated Apr 6, 2024
gatewaymobile-moneyorange-moneypayment-aggregatorwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The e-nkap-woocommerce-gateway plugin version 1.0.8 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices in output escaping, with all 47 detected outputs being properly escaped. Furthermore, there are no recorded vulnerabilities (CVEs) in its history, suggesting a potentially stable and well-maintained codebase. The absence of dangerous functions, file operations, and external HTTP requests also contributes to a reduced attack surface in those specific areas.

However, there are significant concerns regarding the plugin's entry points. Out of 3 total entry points, 2 are unprotected. Specifically, there are 2 REST API routes that lack permission callbacks, exposing them to unauthorized access. While the static analysis did not reveal any dangerous functions or critical taint flows, the presence of unprotected entry points is a substantial risk. The static analysis also found 8 SQL queries, with 50% not using prepared statements, which could potentially lead to SQL injection vulnerabilities if not handled carefully.

In conclusion, while the plugin has strong output handling and a clean vulnerability history, the lack of proper authentication and authorization on its REST API routes represents a critical security weakness. The SQL query practices also warrant attention. Addressing these unprotected entry points and reinforcing SQL query security should be the primary focus for improving the plugin's overall security.

Key Concerns

  • Unprotected REST API routes
  • SQL queries without prepared statements
Vulnerabilities
None known

SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
4 prepared
Unescaped Output
0
47 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

50% prepared8 total queries

Output Escaping

100% escaped47 total outputs
Attack Surface
2 unprotected

SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 1

authwp_ajax_e_nkap_mark_order_statusincludes\admin\PluginAdmin.php:59

REST API Routes 2

GET/wp-json/wc-e-nkap/return/(.*?)includes\Plugin.php:204
PUT/wp-json/wc-e-nkap/notification/(.*?)includes\Plugin.php:226
WordPress Hooks 13
filtermanage_edit-shop_order_columnsincludes\admin\PluginAdmin.php:56
actionmanage_shop_order_posts_custom_columnincludes\admin\PluginAdmin.php:57
filterwoocommerce_admin_order_actionsincludes\admin\PluginAdmin.php:58
actionadmin_enqueue_scriptsincludes\admin\PluginAdmin.php:60
actionwpmu_new_blogincludes\Install.php:15
filterwpmu_drop_tablesincludes\Install.php:16
actionplugins_loadedincludes\Logger\Logger.php:26
filterwoocommerce_payment_gatewaysincludes\Plugin.php:80
actionplugins_loadedincludes\Plugin.php:87
actionwp_enqueue_scriptsincludes\Plugin.php:88
actioninitincludes\Plugin.php:119
actionrest_api_initincludes\Plugin.php:120
actionrest_api_initincludes\Plugin.php:121
Maintenance & Trust

SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 6, 2024
PHP min version7.3
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce Developer Profile

Camoo Sarl

4 plugins · 310 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-nkap-woocommerce-gateway/includes/assets/css/admin-style.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce