
iPaymu Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ipaymu-for-woocommerceiPaymu Payment Gateway for WooCommerce enables secure payments via Virtual Account, QRIS, Minimarket, Credit Card, and Direct Debit in Indonesia.
Is iPaymu Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 97/100iPaymu Payment Gateway for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'ipaymu-for-woocommerce' v2.0.3 demonstrates a generally strong security posture based on the static analysis. It exhibits no detectable dangerous functions, utilizes prepared statements exclusively for its SQL queries, and all identified output is properly escaped. Furthermore, the absence of identified taint flows with unsanitized paths, critical or high severity, is a positive indicator. However, the plugin's vulnerability history reveals one previously known high-severity vulnerability related to missing authorization, and notably, it has a last vulnerability date in the future, which is an anomaly requiring further investigation. The lack of nonce and capability checks on its entry points is a significant concern, as it implies that all AJAX handlers, REST API routes, shortcodes, and cron events are potentially accessible without proper authorization verification, creating a substantial attack surface that is currently unprotected. While the code itself appears to follow good practices for SQL and output handling, the absence of authorization checks on entry points and the peculiar vulnerability history suggest potential weaknesses that could be exploited if not addressed.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- One known high severity vulnerability (unpatched status unclear)
- Future vulnerability date is anomalous
iPaymu Payment Gateway for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
iPaymu Payment Gateway for WooCommerce <= 2.0.2 - Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure
iPaymu Payment Gateway for WooCommerce Code Analysis
Output Escaping
iPaymu Payment Gateway for WooCommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
iPaymu Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
iPaymu Payment Gateway for WooCommerce Alternatives
Payment Gateway Groups for WooCommerce
payment-gateway-groups-for-woocommerce
Allows you to create groups for payment gateways on the checkout page.
Paypercut Payments for WooCommerce
paypercut-payments-for-woocommerce
Paypercut Payments enables WooCommerce merchants to accept online payments using Paypercut's checkout experience.
Mijireh Checkout for Gravity Forms
mijireh-checkout-for-gravity-forms
Mijireh Checkout Plugin for accepting payments on with your Gravity Forms.
Mijireh Checkout for Ninja Forms
mijireh-checkout-for-ninja-forms
Mijireh Checkout Plugin for accepting payments on with your Ninja Forms.
Whalet Payment
whalet-payment
Secure and convenient online payment gateway for WordPress with WooCommerce integration and flexible payment solutions.
iPaymu Payment Gateway for WooCommerce Developer Profile
1 plugin · 40 total installs
How We Detect iPaymu Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.