Monetbil – Mobile Money Gateway for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/monetbil-edd-gateway

A Payment Gateway for Mobile Money Payments - Easy Digital Downloads.

10 active installs v1.15 PHP + WP 3.0+ Updated Jun 16, 2019
easy-digital-downloadseddgatewaypaymentpayment-gateways
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Monetbil – Mobile Money Gateway for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

Monetbil – Mobile Money Gateway for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The security posture of monetbil-edd-gateway v1.15 appears to be reasonably good from a static analysis perspective, with no identified dangerous functions, raw SQL queries, file operations, or critical taint flows. The absence of known vulnerabilities in its history also suggests a history of secure development or diligent patching. However, there are significant concerns regarding output escaping, as only 29% of outputs are properly escaped. This leaves potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without proper sanitization.

While the attack surface is reported as zero entry points, the external HTTP requests introduce a dependency on external services, which could be a vector for supply chain attacks or misconfigurations. The complete lack of nonce checks and capability checks across all identified entry points (if any exist beyond the reported zero) is a major weakness. This indicates that even if there were entry points, they would likely be vulnerable to CSRF attacks or unauthorized access, as they rely solely on the application's internal logic rather than WordPress's built-in security mechanisms.

In conclusion, while monetbil-edd-gateway v1.15 shows strengths in avoiding common SQL and code execution vulnerabilities, the high percentage of unescaped output and the complete absence of nonce and capability checks present substantial risks. These weaknesses, if not addressed, could lead to XSS, CSRF, and unauthorized access vulnerabilities. The plugin's history of no vulnerabilities is a positive sign, but it does not negate the immediate risks identified in the static analysis.

Key Concerns

  • Unescaped output detected
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Monetbil – Mobile Money Gateway for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Monetbil – Mobile Money Gateway for Easy Digital Downloads Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Monetbil – Mobile Money Gateway for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

29% escaped45 total outputs
Attack Surface

Monetbil – Mobile Money Gateway for Easy Digital Downloads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedmonetbil-edd-gateway.php:17
actionedd_gateway_monetbilmonetbil-edd-gateway.php:475
actionedd_monetbil_cc_formmonetbil-edd-gateway.php:476
actionparse_requestmonetbil-edd-gateway.php:477
actionparse_requestmonetbil-edd-gateway.php:478
actionparse_requestmonetbil-edd-gateway.php:479
actionwp_enqueue_scriptsmonetbil-edd-gateway.php:480
filteredd_currenciesmonetbil-edd-gateway.php:482
filteredd_payment_gatewaysmonetbil-edd-gateway.php:483
filteredd_settings_sections_gatewaysmonetbil-edd-gateway.php:484
filteredd_settings_gatewaysmonetbil-edd-gateway.php:485
filteredd_checkout_button_purchasemonetbil-edd-gateway.php:487
filteredd_user_can_view_receiptmonetbil-edd-gateway.php:488
Maintenance & Trust

Monetbil – Mobile Money Gateway for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 16, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Monetbil – Mobile Money Gateway for Easy Digital Downloads Developer Profile

Serge NTONG

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Monetbil – Mobile Money Gateway for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/monetbil-edd-gateway/assets/css/bootstrap.min.css/wp-content/plugins/monetbil-edd-gateway/assets/css/style.css/wp-content/plugins/monetbil-edd-gateway/assets/js/monetbil-mobile-payments.js/wp-content/plugins/monetbil-edd-gateway/assets/js/monetbil.min.js
Script Paths
/wp-content/plugins/monetbil-edd-gateway/assets/js/monetbil-mobile-payments.js/wp-content/plugins/monetbil-edd-gateway/assets/js/monetbil.min.js
Version Parameters
monetbil-edd-gateway/assets/css/bootstrap.min.css?ver=monetbil-edd-gateway/assets/css/style.css?ver=monetbil-edd-gateway/assets/js/monetbil-mobile-payments.js?ver=monetbil-edd-gateway/assets/js/monetbil.min.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/monetbil/edd/notify/monetbil/edd/return
FAQ

Frequently Asked Questions about Monetbil – Mobile Money Gateway for Easy Digital Downloads