
Экспресс Платежи: ЕРИП Security & Risk Analysis
wordpress.org/plugins/express-pay-erip«Экспресс Платежи: ЕРИП» для WooCommerce, плагин для простого подключения приема платежей в системе «ЕРИП» (АИС “Расчет”).
Is Экспресс Платежи: ЕРИП Safe to Use in 2026?
Generally Safe
Score 100/100Экспресс Платежи: ЕРИП has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The express-pay-erip plugin v1.1.5 exhibits a generally good security posture, with no known critical vulnerabilities or past CVEs. The absence of dangerous functions and the consistent use of prepared statements for SQL queries are significant strengths. However, the static analysis reveals areas for improvement. Notably, only 25% of output is properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization. The presence of file operations and external HTTP requests, coupled with a lack of comprehensive capability checks for these actions, introduces potential risks if these operations can be influenced by malicious input. The taint analysis did identify one flow with an unsanitized path, which, while not classified as critical or high severity in this instance, warrants attention for potential future exploitation paths.
Despite these identified weaknesses, the plugin's zero-day vulnerability history is a positive indicator of its development practices to date. The limited attack surface and the presence of at least one capability check are also commendable. The primary concern revolves around output escaping and the potential risks associated with file operations and external requests without robust authorization controls. Overall, the plugin is reasonably secure but could benefit from increased attention to output sanitization and more granular permission checks for sensitive operations.
Key Concerns
- Low percentage of properly escaped output
- File operations without clear auth checks
- External HTTP requests without clear auth checks
- Taint flow with unsanitized path
Экспресс Платежи: ЕРИП Security Vulnerabilities
Экспресс Платежи: ЕРИП Code Analysis
Output Escaping
Data Flow Analysis
Экспресс Платежи: ЕРИП Attack Surface
WordPress Hooks 5
Maintenance & Trust
Экспресс Платежи: ЕРИП Maintenance & Trust
Maintenance Signals
Community Trust
Экспресс Платежи: ЕРИП Alternatives
Экспресс Платежи: E-POS
e-pos
«Экспресс Платежи: E-POS» для WooCommerce, плагин для простого подключения приема платежей в системе E-POS.
Flitt payment gateway for WooCommerce
flitt-payment-gateway-for-woocommerce
The plugin for WooCommerce allows you to integrate the online payment form on the Checkout page of your online store.
Экспресс Платежи: Интернет-Эквайринг
express-pay-card
Описание
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Live eftpos for WooCommerce
live-eftpos-for-woocommerce
The Live eftpos for WooCommerce plugin is the easy way to manage card payments via your online store.
Экспресс Платежи: ЕРИП Developer Profile
3 plugins · 90 total installs
How We Detect Экспресс Платежи: ЕРИП
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/express-pay-erip/assets/css/expresspay-erip-checkout.css/wp-content/plugins/express-pay-erip/assets/js/expresspay-erip-checkout.js/wp-content/plugins/express-pay-erip/assets/js/expresspay-erip-checkout.jsexpress-pay-erip/assets/css/expresspay-erip-checkout.css?ver=express-pay-erip/assets/js/expresspay-erip-checkout.js?ver=HTML / DOM Fingerprints
expresspay-erip-checkout