
ePayco plugin for WooCommerce Security & Risk Analysis
wordpress.org/plugins/epayco-gatewayThe official ePayco plugin for WooCommerce allows seamless payment processing for your online store.
Is ePayco plugin for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ePayco plugin for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "epayco-gateway" v8.4.5 plugin exhibits a generally good security posture, with no known vulnerabilities in its history and a well-defined, albeit small, attack surface. The static analysis shows no unauthenticated entry points, which is a significant strength. However, there are notable areas of concern within the code's implementation.
The plugin's handling of SQL queries is a major weakness, with 100% of queries not using prepared statements. This presents a significant risk of SQL injection vulnerabilities, especially as there are two SQL queries identified. Furthermore, the taint analysis revealed three flows with unsanitized paths. While no critical or high severity issues were flagged by the taint analysis, the presence of unsanitized paths is a red flag that warrants further investigation. The output escaping is mostly robust, but the 21% of outputs not properly escaped could lead to cross-site scripting (XSS) vulnerabilities.
While the plugin's vulnerability history is clean, this does not guarantee future security. The absence of capability checks and nonce checks on potential entry points (even though the attack surface is currently zero) means that if any new entry points are introduced or existing ones become exposed, they might lack essential security measures. The external HTTP requests and the single cron event, while not inherently risky, are potential vectors if not handled securely. Overall, the plugin has a strong foundation by limiting its attack surface, but the unaddressed SQL query practices and unsanitized paths are critical areas that require immediate attention.
Key Concerns
- SQL queries lack prepared statements
- Flows with unsanitized paths
- Output escaping is not fully proper
- No nonce checks
- No capability checks
ePayco plugin for WooCommerce Security Vulnerabilities
ePayco plugin for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ePayco plugin for WooCommerce Attack Surface
WordPress Hooks 25
Scheduled Events 1
Maintenance & Trust
ePayco plugin for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ePayco plugin for WooCommerce Alternatives
IMMAGIT ePayco Payment Gateway for WooCommerce
wc-epayco-payment-gateway
Receive payments by more than 22 means (credit card, digital wallet, bank transfer, cash and more payments) through the ePayco Colombia service in you …
myPOS Checkout
mypos-virtual-for-woocommerce
One-click checkout with instant settlement. Accept all major cards, Apple Pay and Google Pay. No setup costs or monthly fees.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
imoje
imoje
Add payment via imoje to WooCommerce
Dojo for WooCommerce
dojo-for-woocommerce
Extends WooCommerce, allowing you to take payments via Dojo.
ePayco plugin for WooCommerce Developer Profile
2 plugins · 3K total installs
How We Detect ePayco plugin for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/epayco-gateway/assets/css/epayco-css.css/wp-content/plugins/epayco-gateway/assets/js/frontend/admin.js/wp-content/plugins/epayco-gateway/assets/js/frontend/admin.jsepayco-gateway/style.css?ver=epayco-gateway/script.js?ver=HTML / DOM Fingerprints
epayco-cssEpayco add method.Epayco init.Epayco hookdata-epayco-keydata-epayco-order-iddata-epayco-amountdata-epayco-currencydata-epayco-descriptiondata-epayco-name+23 moreEpaycoepaycoepayco_data/wp-json/epayco/v1/payment/wp-json/epayco/v1/confirmation/wp-json/epayco/v1/webhook