Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Security & Risk Analysis

wordpress.org/plugins/knit-pay-upi

Knit Pay UPI simplifies UPI QR code integration for your website and updates the payment status as soon as your customer completes the transaction.

300 active installs v1.9.1.0-beta.1 PHP 8.1+ WP 6.5+ Updated Mar 11, 2026
knit-paypaymentsqr-codeupiwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Safe to Use in 2026?

Generally Safe

Score 100/100

Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The "knit-pay-upi" v1.9.1.0 plugin presents a generally good security posture based on the provided static analysis. It demonstrates positive practices such as 100% usage of prepared statements for SQL queries, a lack of dangerous functions, and no identified taint flows. The limited attack surface of 2 AJAX handlers, with none found to be unprotected, is also a strong positive. However, there are areas for improvement. A 63% rate of proper output escaping indicates a significant portion of outputs are not being sanitized, potentially opening the door to cross-site scripting (XSS) vulnerabilities. Additionally, the absence of capability checks, despite the presence of a nonce check for one entry point, suggests that authorization might not be granularly enforced across all potential interactions. The plugin's clean vulnerability history is encouraging, suggesting a history of responsible development, but it does not negate the risks identified in the current code analysis.

Key Concerns

  • Significant portion of output not escaped
  • Missing capability checks on entry points
Vulnerabilities
None known

Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
31 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
19
Bundled Libraries
0

Output Escaping

63% escaped49 total outputs
Attack Surface

Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

noprivwp_ajax_knit_pay_upi_qr_payment_status_checkgateways\upi-qr\Integration.php:42
authwp_ajax_knit_pay_upi_qr_payment_status_checkgateways\upi-qr\Integration.php:43
WordPress Hooks 3
actionknit_pay_upi_payment_status_checkgateways\upi-qr\Integration.php:46
actionplugins_loadedknit-pay-upi.php:44
filterpronamic_pay_gatewaysknit-pay-upi.php:75

Scheduled Events 1

knit_pay_upi_bharatpe_refresh_connection
Maintenance & Trust

Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 11, 2026
PHP min version8.1
Downloads19K

Community Trust

Rating100/100
Number of ratings4
Active installs300
Developer Profile

Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC Developer Profile

knitpay

6 plugins · 24K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/knit-pay-upi/assets/css/knitpay-upi.css/wp-content/plugins/knit-pay-upi/assets/js/knitpay-upi.js
Script Paths
/wp-content/plugins/knit-pay-upi/assets/js/knitpay-upi.js
Version Parameters
knit-pay-upi/assets/css/knitpay-upi.css?ver=knit-pay-upi/assets/js/knitpay-upi.js?ver=

HTML / DOM Fingerprints

CSS Classes
knitpay-upi-button
HTML Comments
<!-- Knit Pay UPI Plugin v1.9.1.0 --><!-- Prevent loading this file directly -->
Data Attributes
data-knitpay-upi-phonedata-knitpay-upi-amountdata-knitpay-upi-purpose
JS Globals
window.knitpay_upi_params
Shortcode Output
[knitpay_upi_payment_button]
FAQ

Frequently Asked Questions about Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC