
iwocaPay Payment Gateway Security & Risk Analysis
wordpress.org/plugins/iwocapay-payment-gatewayAdd iwocaPay as a payment option to your WooCommerce checkout flow.
Is iwocaPay Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100iwocaPay Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'iwocapay-payment-gateway' plugin, version 1.3.2, exhibits a concerning security posture despite a clean vulnerability history. The static analysis reveals a significant attack surface consisting of four AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these handlers, leading to an exposure of sensitive functionality. The taint analysis further highlights this risk, with four flows analyzed, all involving unsanitized paths, although they are not classified as critical or high severity. This suggests a potential for issues if these paths are exploited, even if not immediately critical. The plugin also demonstrates poor output escaping practices, with only 19% of outputs properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. While the absence of known CVEs and dangerous functions is positive, the lack of nonces and capability checks on critical entry points, combined with the unsanitized taint flows, points to a need for immediate attention to secure these functions.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Low output escaping rate
- No nonce checks on AJAX handlers
- No capability checks on entry points
iwocaPay Payment Gateway Security Vulnerabilities
iwocaPay Payment Gateway Code Analysis
Output Escaping
Data Flow Analysis
iwocaPay Payment Gateway Attack Surface
AJAX Handlers 4
WordPress Hooks 15
Maintenance & Trust
iwocaPay Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
iwocaPay Payment Gateway Alternatives
WooCommerce Payfast Gateway
woocommerce-payfast-gateway
Give customers more flexibility and increase your bottom line with Payfast — one of South Africa’s most popular payment gateways.
Clover Payments for WooCommerce
clover-payments-for-woocommerce
The Clover Payments plugin enables merchants that use WooCommerce to process online card payments using Clover.
Eway Payments for Woo
woocommerce-gateway-eway
This is the official WooCommerce extension to take credit card and subscription payments directly on your store with Eway.
Alma – Pay in installments or later for WooCommerce
alma-gateway-for-woocommerce
This plugin adds a new payment method to WooCommerce, which allows you to offer monthly payments to your customer using Alma.
Peach Payments Gateway
wc-peach-payments-gateway
A payment gateway integration between WooCommerce and Peach Payments.
iwocaPay Payment Gateway Developer Profile
1 plugin · 100 total installs
How We Detect iwocaPay Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iwocapay-payment-gateway/iwp-logo-small.svgHTML / DOM Fingerprints
data-iwocapay-payment-modesdata-iwocapay-seller-iddata-iwocapay-api-keydata-iwocapay-test-modedata-iwocapay-base-urldata-iwocapay-popup-enabled+3 moreiwocapay_payment_gateway_params/wp-json/iwocapay/v1/payment/request