Jamatto Micropayments Security & Risk Analysis

wordpress.org/plugins/jamatto-micropayments

Have you considered turning your blogs into a source of income? In fewer than 30 seconds, Jamatto lets you accept small payments from your readers.

10 active installs v1.7 PHP + WP 3.0.1+ Updated Unknown
donationjamattomicropaymentspremiumpremium-content
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Jamatto Micropayments Safe to Use in 2026?

Generally Safe

Score 100/100

Jamatto Micropayments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The jamatto-micropayments plugin v1.7 appears to have a generally strong security posture based on the static analysis. It demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. The plugin also correctly implements capability checks, though the lack of nonce checks is a notable concern, especially given the presence of shortcodes which can be invoked by users.

The taint analysis revealed one flow with an unsanitized path. While classified as not critical or high, this indicates a potential weakness where user-supplied data might not be sufficiently cleaned before being used in a sensitive operation. This, combined with the lack of nonce checks on the three identified shortcodes, presents a potential avenue for certain types of attacks if user input is not meticulously handled within the shortcode execution.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that the developers have either maintained a high level of security or that the plugin has not been a significant target for widespread vulnerability discovery. However, the absence of historical vulnerabilities does not guarantee future security, and the issues identified in the static analysis should still be addressed.

Key Concerns

  • Taint flow with unsanitized path
  • Shortcodes present without nonce checks
Vulnerabilities
None known

Jamatto Micropayments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Jamatto Micropayments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
52 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped52 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
_JAMATTO_DONATIONS_safe_update_option (jamatto-micropayments.php:258)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Jamatto Micropayments Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[jamatto-donate] jamatto-micropayments.php:130
[jamatto-debug] jamatto-micropayments.php:145
[jamatto-premium] jamatto-micropayments.php:245
WordPress Hooks 3
actionwp_enqueue_scriptsjamatto-micropayments.php:49
filterthe_contentjamatto-micropayments.php:51
actionadmin_menujamatto-micropayments.php:251
Maintenance & Trust

Jamatto Micropayments Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Jamatto Micropayments Developer Profile

jamatto

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jamatto Micropayments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
//cdn.jamatto.com/api/js/jamatto.min.js

HTML / DOM Fingerprints

CSS Classes
jamatto-purchase
Data Attributes
jamatto-bidjamatto-promptjamatto-captionjamatto-amountjamatto-ccyjamatto-item+5 more
Shortcode Output
<i class="jamatto-purchase" jamatto-bid="jamatto-prompt="jamatto-caption="jamatto-amount="
FAQ

Frequently Asked Questions about Jamatto Micropayments