Monnify Official Security & Risk Analysis

wordpress.org/plugins/monnify-official

Monnify Official WooCommerce Payment Gateway plugin provides a seamless payment experience for your customers on your WordPress website.

100 active installs v1.0.3 PHP 7.4+ WP 5.6+ Updated Jan 10, 2026
e-commercemonnifynigeriapayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Monnify Official Safe to Use in 2026?

Generally Safe

Score 100/100

Monnify Official has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "monnify-official" v1.0.3 plugin exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to secure coding practices by not exposing any AJAX handlers or REST API routes without proper authentication checks, and it avoids using shortcodes or cron events. The code also shows positive signs with 100% of SQL queries utilizing prepared statements, which is a critical defense against SQL injection. However, a notable concern arises from the taint analysis, which identified 2 flows with unsanitized paths. While no critical or high severity issues were flagged in the taint analysis, these unsanitized paths still represent potential entry points for malicious data to be processed without adequate validation, which could lead to unexpected behavior or further vulnerabilities if exploited in conjunction with other factors.

The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of stable and relatively secure development. Despite the positive history, the presence of unsanitized paths in the taint analysis warrants attention. The plugin's strengths lie in its minimal attack surface and secure handling of database interactions. The primary weakness, as indicated by the taint analysis, is the need for better sanitization of input paths. Overall, the plugin is likely secure for general use, but the identified taint flows are a point of concern that should be addressed to further harden its security.

Key Concerns

  • Unsanitized paths in taint analysis
  • Low percentage of properly escaped output
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
None known

Monnify Official Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Monnify Official Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Monnify Official Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
17 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

85% escaped20 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
monnify_trans_verify_payment (includes\class-monnify-official.php:519)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Monnify Official Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwp_enqueue_scriptsincludes\class-monnify-official.php:118
actionwoocommerce_available_payment_gatewaysincludes\class-monnify-official.php:119
actionwoocommerce_api_wc_monnify_gatewayincludes\class-monnify-official.php:121
actionadmin_initmonnify-official.php:25
filterwoocommerce_payment_gatewaysmonnify-official.php:30
actionadmin_noticesmonnify-official.php:76
actionadmin_initmonnify-official.php:94
actionplugins_loadedmonnify-official.php:102
actionwoocommerce_blocks_loadedmonnify-official.php:114
actionwoocommerce_blocks_payment_method_type_registrationmonnify-official.php:119
Maintenance & Trust

Monnify Official Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedJan 10, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Monnify Official Developer Profile

Monnify Payment Gateway

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Monnify Official

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/monnify-official/assets/css/style.css/wp-content/plugins/monnify-official/assets/js/main.js/wp-content/plugins/monnify-official/assets/js/checkout.js
Script Paths
/wp-content/plugins/monnify-official/assets/js/main.js/wp-content/plugins/monnify-official/assets/js/checkout.js
Version Parameters
monnify-official/assets/css/style.css?ver=monnify-official/assets/js/main.js?ver=monnify-official/assets/js/checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
monnify-payment-gateway
Data Attributes
data-monnify-public-keydata-monnify-secret-keydata-monnify-contract-code
JS Globals
monnify
FAQ

Frequently Asked Questions about Monnify Official