
Finachub Lipa na Mpesa Checkout for WooCommerce Security & Risk Analysis
wordpress.org/plugins/finachub-checkout-for-m-pesaAccept M-Pesa STK Push payments in WooCommerce. A simple and reliable way to integrate Kenya's most popular payment method.
Is Finachub Lipa na Mpesa Checkout for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Finachub Lipa na Mpesa Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "finachub-checkout-for-m-pesa" plugin v1.3.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the plugin's attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions, all SQL queries utilizing prepared statements, and a very high percentage of outputs being properly escaped. The presence of nonce and capability checks, though limited in number, is also a positive sign. The plugin also has no recorded vulnerability history, which suggests a track record of stability and security.
While the static analysis reveals very few potential concerns, the two external HTTP requests warrant some attention. Although they are not directly flagged as a risk in this data, external requests can introduce vulnerabilities if the remote endpoints are compromised or if data is not handled securely. The taint analysis shows zero flows, which is excellent, and the absence of critical or high-severity issues in the vulnerability history further reinforces its current secure state. Overall, this plugin appears to be well-developed from a security perspective, with its main potential area for scrutiny being the handling of its outbound HTTP communications.
Key Concerns
- External HTTP requests detected
Finachub Lipa na Mpesa Checkout for WooCommerce Security Vulnerabilities
Finachub Lipa na Mpesa Checkout for WooCommerce Code Analysis
Output Escaping
Finachub Lipa na Mpesa Checkout for WooCommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
Finachub Lipa na Mpesa Checkout for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Finachub Lipa na Mpesa Checkout for WooCommerce Alternatives
Campay Woocommerce Payment Gateway
campay-api
CamPay is a Fintech service of the company TAKWID
Payment Gateway for M-PESA Open API on WooCommerce
payment-gateway-for-m-pesa-open-api
The plugin enables the customer to have an option of paying merchants using M-PESA mobile money service from a Wordpress site that has WooCommerce plu …
Bani Payments for WooCommerce
bani-payments-for-woocommerce
Bani for WooCommerce allows merchants seamlessly accept cardless payments from their customers whether that be mobile money payments across Sub-Sahara …
Kopo Kopo for WooCommerce
kopo-kopo-for-woocommerce
Enable instant, secure Lipa na M-PESA payments on your WooCommerce shop and make checkout simple for your customers.
Slek Gateway for WooCommerce
slek-gateway-for-woocommerce
Accept payments from MPESA, Credit Cards, Debit Cards via Slek.org. We host all payment gateways making it flexible to shift between any at will.
Finachub Lipa na Mpesa Checkout for WooCommerce Developer Profile
2 plugins · 370 total installs
How We Detect Finachub Lipa na Mpesa Checkout for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/finachub-checkout-for-m-pesa/assets/css/mpesa-frontend-styles.css/wp-content/plugins/finachub-checkout-for-m-pesa/assets/js/mpesa-waiting.jshttps://fonts.googleapis.com/css2?family=Jost:wght@400;500;600;700&display=swapfinachub-checkout-for-m-pesa/assets/css/mpesa-frontend-styles.css?ver=finachub-checkout-for-m-pesa/assets/js/mpesa-waiting.js?ver=HTML / DOM Fingerprints
mpesa-waiting-bodympesa-waiting-containermpesa-waiting-logompesa-waiting-spinnermpesa-instructionmpesa-waiting-upgrade-noticepromo-boxpromo-icon+2 moredata-order_idwindow.finachub_mpesa_waiting_data