Mobile Pay BD Security & Risk Analysis

wordpress.org/plugins/mobile-pay-bd

Mobile Pay BD is a Payment Gateway for WooCommerce

10 active installs v2.2 PHP 5.2.4+ WP 5.6.0+ Updated Feb 11, 2023
bangladeshdak-bivaggatewaynagadwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mobile Pay BD Safe to Use in 2026?

Generally Safe

Score 85/100

Mobile Pay BD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "mobile-pay-bd" plugin v2.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals a healthy approach to data handling, with no dangerous functions, file operations, or external HTTP requests detected. The use of prepared statements for all SQL queries and a high percentage of properly escaped output further bolster its security.

However, a notable concern arises from the complete lack of nonce checks and capability checks. While the current analysis shows no direct vulnerabilities stemming from this, it represents a critical gap in WordPress security best practices. If any entry points were to be introduced in future versions, or if existing ones were missed in this analysis, the absence of these fundamental security measures would expose the plugin to significant risks like Cross-Site Request Forgery (CSRF) and privilege escalation. The vulnerability history being entirely clear is a positive sign, suggesting a history of secure development or minimal exposure, but it does not negate the identified structural weaknesses.

In conclusion, "mobile-pay-bd" v2.2 demonstrates good practices in code execution and data sanitization, presenting a low immediate risk. Its strengths lie in its minimal attack surface and secure data handling. The primary weakness is the complete omission of nonce and capability checks, which, while not currently exploited, represents a fundamental security deficiency that could lead to severe vulnerabilities if not addressed, especially with any future code additions.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Mobile Pay BD Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Mobile Pay BD Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped20 total outputs
Attack Surface

Mobile Pay BD Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actioninitnagad.php:22
filterwoocommerce_payment_gatewaysnagad.php:31
actionplugins_loadednagad.php:41
filterwoocommerce_thankyou_order_received_textnagad.php:74
actionwoocommerce_email_before_order_tablenagad.php:75
actionwp_enqueue_scriptsnagad.php:218
actionwoocommerce_cart_calculate_feesnagad.php:224
actionwoocommerce_checkout_processnagad.php:257
actionwoocommerce_checkout_update_order_metanagad.php:289
actionwoocommerce_admin_order_data_after_billing_addressnagad.php:309
actionwoocommerce_order_details_after_customer_detailsnagad.php:342
filtermanage_edit-shop_order_columnsnagad.php:368
actionmanage_shop_order_posts_custom_columnnagad.php:384
Maintenance & Trust

Mobile Pay BD Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 11, 2023
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Mobile Pay BD Developer Profile

Md Safiqul Islam

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mobile Pay BD

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-pay-bd/images/nagad.png
Script Paths
/wp-content/plugins/mobile-pay-bd/js/scripts.js

HTML / DOM Fingerprints

JS Globals
window.jQuery
FAQ

Frequently Asked Questions about Mobile Pay BD