
ECPay Ecommerce for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ecpay-ecommerce-for-woocommerce綠界科技外掛套件,提供合作特店以及個人賣家使用開放原始碼商店系統時,無須自行處理複雜的檢核,直接透過安裝設定外掛套件,便可快速介接綠界科技系統,進行金流、物流、電子發票操作。
Is ECPay Ecommerce for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100ECPay Ecommerce for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'ecpay-ecommerce-for-woocommerce' v1.1.2510300 exhibits a mixed security posture. While it demonstrates good practices in utilizing prepared statements for SQL queries and a high percentage of properly escaped outputs, significant concerns arise from its attack surface and taint analysis. The presence of 5 AJAX handlers, with a concerning 4 lacking proper authentication checks, creates a large entry point for potential unauthorized actions. The taint analysis reveals 11 flows with unsanitized paths and 5 high-severity flows, indicating potential vulnerabilities where user-supplied data could be processed in an insecure manner, even if these are not immediately translating to SQL injection or XSS based on the 'Dangerous functions' signal. The vulnerability history, while currently showing no unpatched CVEs and a single medium severity vulnerability in the past related to missing authorization, suggests a recurring pattern of authorization issues. This, combined with the current lack of robust authentication on a majority of its AJAX endpoints, points to a persistent risk that needs careful monitoring and remediation.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows found
- Flows with unsanitized paths
- Past missing authorization vulnerability
- Limited nonce checks
- Limited capability checks
ECPay Ecommerce for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ECPay Ecommerce for WooCommerce <= 1.1.2411060 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
ECPay Ecommerce for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ECPay Ecommerce for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 66
Maintenance & Trust
ECPay Ecommerce for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ECPay Ecommerce for WooCommerce Alternatives
Jigoshop Credimax
jigoshop-credimax
This plugin extends the Jigoshop payment gateways to add in Credimax Payment Gateway.
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler
fluent-cart
Sell Subscriptions, Physical Products, Digital Downloads easier than ever. Built for performance, scalability, and flexibility.
Payment Button for PayPal
wp-paypal
Easily accept payment in WordPress by adding a PayPal button to your website. Add PayPal Buy Now, Add to Cart, Subscription or Donation button.
Mini Cart for WooCommerce – Add a Stylish Sliding Cart
mini-cart-for-woocommerce
It allows to creation of a beautiful Mini Cart on the WooCommerce site. Adds cart icon to menu and body.
BORICA Payments by BORICA AD
borica-payments
Simple way of receiving debit and credit card payments by virtual POS.
ECPay Ecommerce for WooCommerce Developer Profile
2 plugins · 1K total installs
How We Detect ECPay Ecommerce for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ecpay-ecommerce-for-woocommerce/includes/services/helpers/logger/ecpay-logger.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/includes/services/payment/class-wooecpay-gateway.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/includes/services/logistic/class-wooecpay-logistic.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/includes/services/invoice/checkout-blocks-initialize.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/includes/services/invoice/class-wooecpay-invoice.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/admin/settings/class-wooecpay-setting.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/admin/order/class-wooecpay-order.php/wp-content/plugins/ecpay-ecommerce-for-woocommerce/includes/services/helpers/logistic/ecpay-logistic-helper.php+4 moreECPay Ecommerce for WooCommerce 1.1.2510300ecpay-ecommerce-for-woocommerce/style.css?ver=ecpay-ecommerce-for-woocommerce/script.js?ver=HTML / DOM Fingerprints
wooecpay-order-actions<!-- ECPay Order Actions --><!-- Logistic Button --><!-- check_order_status_cancel --><!-- check_order_is_duplicate_payment -->data-ecpay-logistic-actiondata-ecpay-duplicate-payment-actionwindow.wooecpay_settingswindow.wooecpay_ajax_object/wp-json/wooecpay/v1/logistic/wp-json/wooecpay/v1/payment