ham3da integration for OxaPay Security & Risk Analysis

wordpress.org/plugins/ham3da-integration-for-oxapay-in-woocommerce

Accept cryptocurrency payments on your WooCommerce store.

0 active installs v1.1.2 PHP 7.2+ WP 5.0+ Updated Unknown
bitcoinbnbcrypto-paymentpayment-gatewayusdt
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ham3da integration for OxaPay Safe to Use in 2026?

Generally Safe

Score 100/100

ham3da integration for OxaPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of ham3da-integration-for-oxapay-in-woocommerce v1.1.2 indicates a generally good security posture, with no identified dangerous functions, SQL injection vulnerabilities, or output escaping issues. The plugin also demonstrates a lack of critical or high severity taint flows, and a clean vulnerability history with no known CVEs. This suggests the developers have implemented some good security practices.

However, there are notable concerns. The complete absence of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron events) is a significant weakness. This means that any functionality accessible through these methods is effectively unprotected and could be exploited by unauthenticated users. The presence of file operations and external HTTP requests, while not inherently malicious, represent potential vectors for further exploitation if not carefully handled.

In conclusion, while the plugin avoids common pitfalls like raw SQL queries and unsanitized output, the lack of authentication and authorization checks on its entry points is a critical security deficiency. The absence of historical vulnerabilities is positive but does not mitigate the current lack of protective measures in the code. A user of this plugin should be aware of these significant risks.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

ham3da integration for OxaPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ham3da integration for OxaPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

ham3da integration for OxaPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionbefore_woocommerce_initham3da-integration-for-oxapay-in-woocommerce.php:33
actionplugins_loadedham3da-integration-for-oxapay-in-woocommerce.php:45
filterwoocommerce_payment_gatewaysham3da-integration-for-oxapay-in-woocommerce.php:49
actionwoocommerce_order_details_after_order_tableham3da-integration-for-oxapay-in-woocommerce.php:52
actionwoocommerce_blocks_payment_method_type_registrationham3da-integration-for-oxapay-in-woocommerce.php:57
actionwoocommerce_blocks_loadedham3da-integration-for-oxapay-in-woocommerce.php:65
actionwoocommerce_review_order_after_order_totalham3da-integration-for-oxapay-in-woocommerce.php:69
actionadmin_enqueue_scriptsinc\gateway-class.php:57
actionwp_enqueue_scriptsinc\gateway-class.php:58
actioninitinc\gateway-class.php:60
Maintenance & Trust

ham3da integration for OxaPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.2
Downloads333

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ham3da integration for OxaPay Developer Profile

Javad Ehteshami

6 plugins · 90 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ham3da integration for OxaPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ham3da-integration-for-oxapay-in-woocommerce/assets/images/oxapay.png

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wc/v3/products/wp-json/wp/v2/users/wp-json/wc/v3/orders
FAQ

Frequently Asked Questions about ham3da integration for OxaPay