
Экспресс Платежи: Интернет-Эквайринг Security & Risk Analysis
wordpress.org/plugins/express-pay-cardОписание
Is Экспресс Платежи: Интернет-Эквайринг Safe to Use in 2026?
Generally Safe
Score 100/100Экспресс Платежи: Интернет-Эквайринг has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The express-pay-card plugin version 1.1.3 exhibits a generally positive security posture due to its limited attack surface and the absence of known vulnerabilities. The static analysis reveals no direct entry points like AJAX handlers, REST API routes, or shortcodes without authentication, which is a significant strength. The plugin also correctly utilizes prepared statements for its SQL queries and includes capability checks, demonstrating good coding practices.
However, concerns arise from the output escaping. With 47% of outputs properly escaped, there's a significant portion that is not. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed to users. Additionally, the taint analysis identified one flow with unsanitized paths, although it was not classified as critical or high severity. This, combined with the file operations, warrants further investigation to ensure these operations are secure and do not expose sensitive information or allow for unauthorized file modifications.
Given the complete lack of historical vulnerabilities, the plugin appears to be maintained with security in mind. However, the identified output escaping weakness and the taint flow involving unsanitized paths are areas that require immediate attention. While the plugin's current security is relatively strong due to its minimal attack surface and absence of direct exploits, these identified code-level concerns represent potential risks that could be exploited in the future if not addressed.
Key Concerns
- Insufficient output escaping
- Unsanitized paths in taint flow
Экспресс Платежи: Интернет-Эквайринг Security Vulnerabilities
Экспресс Платежи: Интернет-Эквайринг Code Analysis
Output Escaping
Data Flow Analysis
Экспресс Платежи: Интернет-Эквайринг Attack Surface
WordPress Hooks 5
Maintenance & Trust
Экспресс Платежи: Интернет-Эквайринг Maintenance & Trust
Maintenance Signals
Community Trust
Экспресс Платежи: Интернет-Эквайринг Alternatives
Экспресс Платежи: E-POS
e-pos
«Экспресс Платежи: E-POS» для WooCommerce, плагин для простого подключения приема платежей в системе E-POS.
Flitt payment gateway for WooCommerce
flitt-payment-gateway-for-woocommerce
The plugin for WooCommerce allows you to integrate the online payment form on the Checkout page of your online store.
Экспресс Платежи: ЕРИП
express-pay-erip
«Экспресс Платежи: ЕРИП» для WooCommerce, плагин для простого подключения приема платежей в системе «ЕРИП» (АИС “Расчет”).
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Live eftpos for WooCommerce
live-eftpos-for-woocommerce
The Live eftpos for WooCommerce plugin is the easy way to manage card payments via your online store.
Экспресс Платежи: Интернет-Эквайринг Developer Profile
3 plugins · 90 total installs
How We Detect Экспресс Платежи: Интернет-Эквайринг
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/express-pay-card/assets/js/expresspay-card-checkout.js/wp-content/plugins/express-pay-card/assets/css/expresspay-card-checkout.css/wp-content/plugins/express-pay-card/assets/js/expresspay-card-checkout.jsexpresspay-card-checkout.js?ver=expresspay-card-checkout.css?ver=HTML / DOM Fingerprints
expresspay-card-gateway-descriptionwindow.expressPayCard