
FM: QR Code Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/fm-qr-code-gatewayAccept UPI payments via QR code in WooCommerce. Customers enter Transaction ID at checkout. Lightweight & easy to configure.
Is FM: QR Code Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100FM: QR Code Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fm-qr-code-gateway" plugin, version 1.0.1, exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, external HTTP requests, or SQL queries without prepared statements is a significant strength. Furthermore, the consistent use of output escaping for all identified outputs and the lack of critical or high-severity taint flows suggest a developer mindful of common web application vulnerabilities. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a low historical risk.
However, the static analysis reports zero nonce checks and zero capability checks. While the current entry point count is zero, this lack of checks on potential future or currently undetected entry points represents a potential weakness. If new AJAX handlers, REST API routes, or other interfaces are introduced in future versions without proper authentication and authorization, the plugin could become vulnerable. The clean vulnerability history is positive, but it is crucial to recognize that this is a snapshot of the current state and doesn't guarantee future security without continued diligence.
In conclusion, the "fm-qr-code-gateway" plugin appears to be developed with good security practices regarding code execution and data handling. The primary area of concern lies in the complete absence of nonce and capability checks, which, while not currently exploitable due to the limited attack surface, leaves room for future vulnerabilities if the plugin evolves. Continuous monitoring and adherence to WordPress security best practices for new feature development are recommended.
Key Concerns
- Missing nonce checks
- Missing capability checks
FM: QR Code Gateway for WooCommerce Security Vulnerabilities
FM: QR Code Gateway for WooCommerce Code Analysis
Output Escaping
FM: QR Code Gateway for WooCommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
FM: QR Code Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
FM: QR Code Gateway for WooCommerce Alternatives
Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC
knit-pay-upi
Knit Pay UPI simplifies UPI QR code integration for your website and updates the payment status as soon as your customer completes the transaction.
UPI QR Code Payment Gateway for WooCommerce
upi-qr-code-payment-for-woocommerce
This Plugin enables WooCommerce shop owners to get direct and instant payments through UPI apps like BHIM, GooglePay, PhonePe or any banking UPI app.
Amazon Pay for WooCommerce
woocommerce-gateway-amazon-payments-advanced
Install the Amazon Pay plugin for your WooCommerce store and take advantage of a seamless checkout experience
myPOS Checkout
mypos-virtual-for-woocommerce
One-click checkout with instant settlement. Accept all major cards, Apple Pay and Google Pay. No setup costs or monthly fees.
ePayco plugin for WooCommerce
epayco-gateway
The official ePayco plugin for WooCommerce allows seamless payment processing for your online store.
FM: QR Code Gateway for WooCommerce Developer Profile
2 plugins · 30 total installs
How We Detect FM: QR Code Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fm-qr-code-gateway/assets/js/fm-qr-checkout.js/wp-content/plugins/fm-qr-code-gateway/assets/js/fm-qr-checkout.js