
Easypay Mobile Money Security & Risk Analysis
wordpress.org/plugins/easypay-mobile-moneyAllow mobile money (MTN,Airtel,M-Sente & Africell Money), Visa & Mastercard payments within your woocommerce stores and wordpress.
Is Easypay Mobile Money Safe to Use in 2026?
Generally Safe
Score 85/100Easypay Mobile Money has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The easypay-mobile-money plugin v1.2.0 exhibits a mixed security posture. While there is no recorded vulnerability history and no critical findings in taint analysis, several concerning aspects in the static analysis warrant attention. The presence of an unprotected AJAX handler significantly expands the attack surface and presents a clear entry point for unauthenticated attackers. Furthermore, the complete absence of capability checks on any entry points is a major weakness, as it implies that any user, regardless of their role or permissions, could potentially trigger plugin functionality. The limited proper output escaping is also a concern, potentially leading to cross-site scripting vulnerabilities if user-supplied data is reflected in the output without sufficient sanitization.
While the lack of dangerous functions and SQL injection vulnerabilities (implied by the 0% prepared statements for its single SQL query) are positive signs, the identified weaknesses are substantial. The unprotected AJAX handler and the lack of capability checks are critical oversight. The low percentage of properly escaped output suggests a general lack of secure coding practices in handling user-generated content. In conclusion, despite a clean vulnerability history, the current version of easypay-mobile-money has significant security flaws in its code that could be exploited. Improvements in input validation, output escaping, and robust authorization checks are strongly recommended.
Key Concerns
- AJAX handler without authentication
- No capability checks on entry points
- Low percentage of properly escaped output
- SQL queries not using prepared statements
Easypay Mobile Money Security Vulnerabilities
Easypay Mobile Money Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Easypay Mobile Money Attack Surface
AJAX Handlers 9
WordPress Hooks 14
Maintenance & Trust
Easypay Mobile Money Maintenance & Trust
Maintenance Signals
Community Trust
Easypay Mobile Money Alternatives
Bykea.Cash – Online Payments
bykea-cash-online-payments
The Bykea Cash plugin allows you to collect payments on your WordPress WooCommerce website instantly using Credit/Debit Cards (VISA, MasterCard, PayPa …
Payment Gateway for Sparco on WooCommerce
wc-sparco-payment-gateway
The plugin allows merchants to accept Visa, Mastercard, MTN Mobile Money Zambia, Airtel Money Zambia and Zamkwacha payments.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Frisbii Pay
reepay-checkout-gateway
Accept Visa, MasterCard, Dankort, MobilePay, American Express, Diners Club and more directly on your store with the Frisbii Pay Gateway.
KKiapay WooCommerce Plugin
kkiapay-woocommerce
Accept Mobile money, direct bank and credit card payments with KKiapay
Easypay Mobile Money Developer Profile
1 plugin · 80 total installs
How We Detect Easypay Mobile Money
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easypay-mobile-money/assets/css/intlTelInput.css/wp-content/plugins/easypay-mobile-money/assets/css/card.css/wp-content/plugins/easypay-mobile-money/assets/css/easypay.css/wp-content/plugins/easypay-mobile-money/assets/css/sweetalert2.min.css/wp-content/plugins/easypay-mobile-money/assets/css/espay_wizard.css/wp-content/plugins/easypay-mobile-money/assets/js/intlTelInput.min.js/wp-content/plugins/easypay-mobile-money/assets/js/jquery.creditCardValidator.js/wp-content/plugins/easypay-mobile-money/assets/js/easypay.js+2 more/wp-content/plugins/easypay-mobile-money/assets/js/intlTelInput.min.js/wp-content/plugins/easypay-mobile-money/assets/js/jquery.creditCardValidator.js/wp-content/plugins/easypay-mobile-money/assets/js/easypay.js/wp-content/plugins/easypay-mobile-money/assets/js/sweetalert2.min.js/wp-content/plugins/easypay-mobile-money/assets/js/intlTelInput.min.js/wp-content/plugins/easypay-mobile-money/assets/js/espay_script.jsHTML / DOM Fingerprints
easypay-setup-wizard-containerdata-easypay-phone-numbereasypay_dataeasypay_phone_update_order_statuseasypay_chk_order_statusespy_resendeasypayrequesteasypay_visa_order_process/wp-json/easypay/v1/process_order/wp-json/easypay/v1/update_order_status