
MANGOPAY for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mangopay-woocommerceOfficial WooCommerce Payment gateway for the MANGOPAY payment solution dedicated to marketplaces.
Is MANGOPAY for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100MANGOPAY for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mangopay-woocommerce" plugin v3.6.3 presents a mixed security posture. While it demonstrates strengths in areas like SQL query protection and output escaping, significant concerns exist regarding its attack surface and handling of sensitive operations. The plugin exposes a substantial number of AJAX handlers, a majority of which lack authentication checks. This, coupled with the presence of the `unserialize` function and unsanitized taint flows, creates a notable risk of unauthorized actions and potential code execution. The absence of nonce checks on these unprotected AJAX endpoints is particularly worrying, as it leaves them vulnerable to Cross-Site Request Forgery (CSRF) attacks.
The plugin's vulnerability history is notably clean, with no recorded CVEs. This is a positive indicator and suggests good development practices historically. However, this clean record should not overshadow the direct risks identified in the static analysis. The current code signals, particularly the unprotected AJAX endpoints and the potential for unsanitized data processing via `unserialize` and taint flows, warrant immediate attention. Therefore, while the plugin has a good track record, the identified vulnerabilities in the current version suggest a need for urgent remediation to maintain its security.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function unserialize
- High severity taint flow
- Unsanitized paths in taint flows
- Missing nonce checks
MANGOPAY for WooCommerce Security Vulnerabilities
MANGOPAY for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MANGOPAY for WooCommerce Attack Surface
AJAX Handlers 12
Shortcodes 3
WordPress Hooks 86
Maintenance & Trust
MANGOPAY for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
MANGOPAY for WooCommerce Alternatives
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
MANGOPAY for WooCommerce Developer Profile
1 plugin · 90 total installs
How We Detect MANGOPAY for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mangopay-woocommerce/assets/css/mangopay-admin.css/wp-content/plugins/mangopay-woocommerce/assets/css/mangopay-checkout.css/wp-content/plugins/mangopay-woocommerce/assets/js/mangopay-admin.js/wp-content/plugins/mangopay-woocommerce/assets/js/mangopay-checkout.js/wp-content/plugins/mangopay-woocommerce/assets/js/mangopay-admin.js/wp-content/plugins/mangopay-woocommerce/assets/js/mangopay-checkout.jsmangopay-woocommerce/assets/css/mangopay-admin.css?ver=mangopay-woocommerce/assets/css/mangopay-checkout.css?ver=mangopay-woocommerce/assets/js/mangopay-admin.js?ver=mangopay-woocommerce/assets/js/mangopay-checkout.js?ver=HTML / DOM Fingerprints
mangopay-admin-wrapmangopay-payment-method-form<!-- IMPORTANT : The admin notices section begins here --><!-- IMPORTANT : The admin notices section ends here -->data-mangopay-checkoutdata-mangopay-walletmangopay_checkout_params/wp-json/mangopay-woocommerce/v1/process_payment