
IntaSend Pay Button Security & Risk Analysis
wordpress.org/plugins/intasend-pay-buttonSecurely collect M-Pesa and card payments (Visa and Mastercard).
Is IntaSend Pay Button Safe to Use in 2026?
Generally Safe
Score 92/100IntaSend Pay Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "intasend-pay-button" v1.0.9 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of unpatched CVEs in its history is a significant positive indicator, suggesting a history of responsible development and timely patching. Furthermore, the code demonstrates good practices regarding output escaping (100% properly escaped) and judicious use of prepared statements for SQL queries (77%). The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes exposed without proper checks, is also commendable.
However, a closer look at the taint analysis reveals a potential concern: one flow with an unsanitized path identified as "High severity". This indicates a possible vulnerability where user-supplied input might be used in a way that could lead to unexpected or malicious behavior, such as directory traversal or file manipulation, even if the static analysis didn't flag specific dangerous functions or file operations. The absence of capability checks across all entry points is also a weakness, as it means that access to functionalities might not be properly restricted based on user roles. While the vulnerability history is clean, the presence of an unsanitized path flow is the most significant risk identified.
In conclusion, while the plugin has a positive track record and good coding hygiene in many areas, the identified high-severity taint flow is a critical point of concern that requires immediate attention. The lack of capability checks, while not as severe as the taint flow, also represents an area for improvement to ensure robust access control. Addressing the unsanitized path is paramount to maintaining a secure plugin.
Key Concerns
- High severity taint flow with unsanitized path
- No capability checks on entry points
IntaSend Pay Button Security Vulnerabilities
IntaSend Pay Button Release Timeline
IntaSend Pay Button Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IntaSend Pay Button Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
IntaSend Pay Button Maintenance & Trust
Maintenance Signals
Community Trust
IntaSend Pay Button Alternatives
IntaSend Payment
intasend-payment
Securely collect M-Pesa and card payments (Visa and Mastercard) (WooCommerce Plugin).
Pagadito Payment Gateway for WooCommerce
woo-pagadito-payment-gateway
Pagadito allows you to pay online in a safe, easy and reliable way.
BudPay
budpay
Accept both international and local payments on from your store.
Bykea.Cash – Online Payments
bykea-cash-online-payments
The Bykea Cash plugin allows you to collect payments on your WordPress WooCommerce website instantly using Credit/Debit Cards (VISA, MasterCard, PayPa …
Tip My Work – HostJane Payments
tip-my-work-hostjane-payments
Accept payments for your work with HostJane, a fast-growing marketplace for freelance services and web hosting provider.
IntaSend Pay Button Developer Profile
2 plugins · 460 total installs
How We Detect IntaSend Pay Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/intasend-pay-button/assets/js/intasend-inline-min.js/wp-content/plugins/intasend-pay-button/assets/js/intasend-pay-btn.js/wp-content/plugins/intasend-pay-button/assets/css/style.cssassets/js/intasend-inline-min.jsassets/js/intasend-pay-btn.jsversion=1.0.0HTML / DOM Fingerprints
intaSendCustomBtnisPayBtn-data-card_tarrifdata-mobile_tarrifdata-amountdata-currencydata-redirect_urldata-api_ref+3 moreintBtnData<button class="intaSendCustomBtn isPayBtn-<input id="isPayEmail-<input id="isPayAmount-