Flying Pay Security & Risk Analysis

wordpress.org/plugins/flying-pay-gateway

A seamless and secure payment gateway integration for WooCommerce featuring Mobile Banking, 4 Major Banks, and Crypto support with an interactive UI.

30 active installs v1.1.3 PHP + WP 5.0+ Updated Mar 9, 2026
bangladeshi-gatewaybd-gatewaybd-payment-gatewaybkashnagad
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flying Pay Safe to Use in 2026?

Generally Safe

Score 100/100

Flying Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "flying-pay-gateway" v1.1.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate diligent security practices, with 100% of SQL queries using prepared statements and 99% of outputs being properly escaped. The presence of nonce checks is also a positive indicator. The vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development or effective patching. However, the complete lack of capability checks, while potentially intentional given the limited entry points, could be a concern if any unforeseen entry points are discovered or introduced in future versions. The taint analysis showing no flows with unsanitized paths further reinforces the perceived security of this version.

While the plugin appears to be very secure in its current state, the zero capability checks is a notable absence. Ideally, even with a minimal attack surface, some level of authorization should be enforced on any interaction points, however small. The absence of any recorded vulnerabilities in its history is a significant strength, indicating either a mature and stable codebase or a consistent effort to address security issues promptly. The combination of a small, well-defended attack surface, good coding practices, and a clean vulnerability history makes this plugin appear to be low risk.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

Flying Pay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Flying Pay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
92 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped93 total outputs
Attack Surface

Flying Pay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesflying-pay-gateway.php:16
actionplugins_loadedflying-pay-gateway.php:26
actionwp_enqueue_scriptsflying-pay-gateway.php:43
filterwoocommerce_payment_gatewaysflying-pay-gateway.php:259
Maintenance & Trust

Flying Pay Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version
Downloads461

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Flying Pay Developer Profile

Rakib Hussain

2 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flying Pay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flying-pay-gateway/includes/css/flying-pay-style.css/wp-content/plugins/flying-pay-gateway/includes/js/flying-pay-script.js/wp-content/plugins/flying-pay-gateway/includes/images/logo.png/wp-content/plugins/flying-pay-gateway/includes/images/bkash.png/wp-content/plugins/flying-pay-gateway/includes/images/nagad.png/wp-content/plugins/flying-pay-gateway/includes/images/rocket.png/wp-content/plugins/flying-pay-gateway/includes/images/al-arafa-islami-bank.png/wp-content/plugins/flying-pay-gateway/includes/images/Pubali-Bank-plc.png+4 more
Script Paths
/wp-content/plugins/flying-pay-gateway/includes/js/flying-pay-script.js
Version Parameters
flying-pay-gateway/includes/css/flying-pay-style.css?ver=flying-pay-gateway/includes/js/flying-pay-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
flying-pay-formflying-pay-options
HTML Comments
<!-- Flying Pay Gateway Plugin Use Korar Jonno Donnobad ❤️ -->
Data Attributes
data-flyingpay-iddata-flyingpay-title
JS Globals
flyingPayScripts
FAQ

Frequently Asked Questions about Flying Pay