Loya Pay Security & Risk Analysis

wordpress.org/plugins/loya-pay

Give your customers 5% instant cashback and 1% referral rewards with Loya Pay.

0 active installs v2.0.2 PHP 7.4+ WP 5.0+ Updated Jan 16, 2026
cashbackloyaltypaymentsrewardswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Loya Pay Safe to Use in 2026?

Generally Safe

Score 100/100

Loya Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "loya-pay" v2.0.2 exhibits a generally good security posture with several positive indicators. The static analysis reveals no critical code signals like dangerous functions or unsanitized taint flows. All output is properly escaped, and file operations and external HTTP requests, while present, are not immediately flagged as issues without further context. The plugin also demonstrates good practice by including capability checks and not bundling external libraries, which can often be a source of vulnerabilities.

However, there are a few areas of concern that prevent a perfect score. The presence of two SQL queries that do not use prepared statements is a significant risk. This makes the plugin vulnerable to SQL injection attacks if the data used in these queries is not meticulously sanitized. Additionally, the complete lack of nonce checks, while not directly tied to an exposed AJAX or REST API endpoint in this specific analysis, is a missed security control. Nonces are a fundamental defense against CSRF attacks, and their absence leaves potential for future vulnerabilities if new endpoints are introduced without proper protection.

Given the absence of any recorded vulnerabilities (CVEs) and the clean taint analysis, the plugin has a history of appearing secure. This suggests the developers are generally mindful of security. Nevertheless, the identified SQL query and nonce check issues represent concrete, evidence-backed risks that warrant attention. The plugin's strengths lie in its proper output escaping and limited attack surface, but the SQL and nonce weaknesses are notable.

Key Concerns

  • SQL queries without prepared statements
  • No nonce checks implemented
Vulnerabilities
None known

Loya Pay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Loya Pay Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

100% escaped11 total outputs
Attack Surface

Loya Pay Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/loya/v1/session-lookuploya-pay.php:553
WordPress Hooks 10
actionbefore_woocommerce_initloya-pay.php:24
actionbefore_woocommerce_initloya-pay.php:31
actionplugins_loadedloya-pay.php:37
actionwp_enqueue_scriptsloya-pay.php:66
filterwoocommerce_payment_gatewaysloya-pay.php:450
actionwoocommerce_api_loya_webhookloya-pay.php:456
actionwoocommerce_blocks_payment_method_type_registrationloya-pay.php:512
actionrest_api_initloya-pay.php:552
actionwp_loadedloya-pay.php:618
actionadmin_noticesloya-pay.php:735
Maintenance & Trust

Loya Pay Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 16, 2026
PHP min version7.4
Downloads151

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Loya Pay Developer Profile

Geoffroyf

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Loya Pay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/loya-pay/assets/css/checkout.css/wp-content/plugins/loya-pay/assets/loya-checkout.js
Script Paths
/wp-content/plugins/loya-pay/assets/loya-checkout.js
Version Parameters
loya-pay/assets/css/checkout.css?ver=loya-pay/assets/loya-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
loya-connect-button
Data Attributes
data-loya-platform-urldata-merchant-iddata-api-keydata-webhook-secretdata-testmode
JS Globals
loya_checkout_params
FAQ

Frequently Asked Questions about Loya Pay