Mintpay Security & Risk Analysis

wordpress.org/plugins/mintpay

Mintpay, Sri Lanka's first buy now, pay later platform offers 0% interest and no hidden fees.

600 active installs v2.2.0 PHP 7.0+ WP 4.6+ Updated May 28, 2025
bnplmintpayonlinepaymentssri-lanka
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mintpay Safe to Use in 2026?

Generally Safe

Score 100/100

Mintpay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The mintpay plugin v2.2.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. There are no identified critical or high-severity vulnerabilities in the code, and the plugin has a clean history with no recorded CVEs. The absence of dangerous functions, raw SQL queries, and file operations is commendable. The plugin also correctly utilizes prepared statements for its SQL queries, which is a significant security best practice. However, the analysis does reveal some areas for improvement. Specifically, the output escaping is only 50% properly implemented, meaning there's a risk of cross-site scripting (XSS) vulnerabilities if the unescaped outputs handle user-supplied data without proper sanitization.

Furthermore, the plugin performs external HTTP requests, which could be a vector for certain types of attacks if not handled with extreme care regarding the data sent and received. The lack of nonce checks and capability checks on any entry points, while currently mitigated by the zero attack surface, represents a potential weakness should any new entry points be introduced in future versions without proper security controls. The overall security is good due to the lack of direct vulnerabilities, but the unescaped outputs and the potential risk associated with external HTTP requests warrant attention.

Key Concerns

  • Unescaped output detected
  • External HTTP requests made
Vulnerabilities
None known

Mintpay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mintpay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

50% escaped6 total outputs
Attack Surface

Mintpay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actioninitgateway\index.php:46
actioninitgateway\index.php:47
actionwoocommerce_receipt_mintpaygateway\index.php:58
actionplugins_loadedindex.php:35
filterwoocommerce_payment_gatewaysindex.php:38
actionwoocommerce_blocks_loadedindex.php:44
actionplugins_loadedindex.php:50
actionwoocommerce_blocks_payment_method_type_registrationindex.php:123
actionadmin_noticesindex.php:138
actionwp_enqueue_scriptsprice-breakdown\index.php:12
filterwoocommerce_available_variationprice-breakdown\index.php:247
filterwoocommerce_get_price_htmlprice-breakdown\index.php:282
actionwoocommerce_review_order_before_paymentprice-breakdown\index.php:367
Maintenance & Trust

Mintpay Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMay 28, 2025
PHP min version7.0
Downloads8K

Community Trust

Rating60/100
Number of ratings2
Active installs600
Developer Profile

Mintpay Developer Profile

mintpay

1 plugin · 600 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mintpay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mintpay/assets/style.css/wp-content/plugins/mintpay/assets/script.js
Script Paths
/wp-content/plugins/mintpay/assets/script.js
Version Parameters
mintpay_stylemintpay_script

HTML / DOM Fingerprints

JS Globals
wp
FAQ

Frequently Asked Questions about Mintpay