[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-eLU0Ud1X_M3o48ML0KYq4kTPamRKtY1JjrYg6rhKK8":3,"$faARGmcggFhdeO5adaNrP8H9SIbp-0jkKgAhBq463Ecs":269,"$fD4VN6KoWmcCYvlsWHp8ZkAW3Hjx7IN3PMSVKzkWDsoE":273},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":35,"analysis":121,"fingerprints":246},"monnify-official","Monnify Official","1.0.3","Monnify Payment Gateway","https:\u002F\u002Fprofiles.wordpress.org\u002Fmonnify\u002F","\u003Cp>Monnify Official WooCommerce Payment Gateway Plugin enables seamless integration to Monnify, a reliable and secure payment gateway, into your WordPress e-commerce website. With Monnify, you can accept payments through multiple payment methods, providing your customers with a smooth and secure checkout experience.\u003C\u002Fp>\n\u003Ch4>Key features include:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easy setup and configuration\u003C\u002Fli>\n\u003Cli>Support for multiple payment methods including card payments and bank transfers\u003C\u002Fli>\n\u003Cli>Real-time transaction monitoring and reporting\u003C\u002Fli>\n\u003Cli>Enhanced security features to protect your customers’ data\u003C\u002Fli>\n\u003Cli>Seamless integration with popular e-commerce plugins\u003C\u002Fli>\n\u003Cli>Supports WooCommerce block checkout\u003C\u002Fli>\n\u003Cli>Compatible with both single-site and WordPress Multisite\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Whether you’re running a small online store or a large e-commerce platform, Monnify Official Plugin is the ideal solution for accepting payments and managing transactions with ease.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to Monnify’s external payment gateway API in order to securely process payments made through the WooCommerce checkout page. It uses Monnify’s JavaScript SDK to initiate and manage payment transactions.\u003Cbr \u002F>\n\u003Cstrong>What data is sent and when:\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen a customer initiates payment at checkout, the plugin loads the Monnify JavaScript SDK (\u003Ccode>https:\u002F\u002Fsdk.monnify.com\u002Fplugin\u002Fmonnify.js\u003C\u002Fcode>) and sends necessary transaction details such as the amount, customer name, email address, and transaction reference to Monnify’s API. These details are required to initiate and validate the payment.\u003Cbr \u002F>\n\u003Cstrong>Why this data is sent:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe data is sent to facilitate real-time payment processing via Monnify’s secure infrastructure, enabling the customer to complete their order.\u003Cbr \u002F>\n\u003Cstrong>Service provider:\u003C\u002Fstrong>\u003Cbr \u002F>\nMonnify\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fmonnify.com\u002Fterms.html\" rel=\"nofollow ugc\">Monnify Terms of Service\u003C\u002Fa>\u003Cbr \u002F>\n– \u003Ca href=\"https:\u002F\u002Fmonnify.com\u002Fprivacy-policy.html\" rel=\"nofollow ugc\">Monnify Privacy Policy\u003C\u002Fa>\u003C\u002Fp>\n","Monnify Official WooCommerce Payment Gateway plugin provides a seamless payment experience for your customers on your WordPress website.",100,1027,1,"2026-01-10T10:07:00.000Z","6.9.5","5.6","7.4",[19,20,21,22,23],"e-commerce","monnify","nigeria","payment-gateway","woocommerce","https:\u002F\u002Fgithub.com\u002FMonnify\u002Fmonnify-wordpress-plugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmonnify-official.1.0.3.zip",0,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":20,"display_name":7,"profile_url":8,"plugin_count":13,"total_installs":11,"avg_security_score":11,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},30,94,"2026-08-29T07:14:39.878Z",[36,57,74,92,104],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":46,"num_ratings":47,"last_updated":48,"tested_up_to":49,"requires_at_least":50,"requires_php":51,"tags":52,"homepage":51,"download_link":55,"security_score":56,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"e-transactions-wc","Up2pay e-Transactions WooCommerce Payment Gateway","3.0.9","Verifone e-commerce","https:\u002F\u002Fprofiles.wordpress.org\u002Fpaybox\u002F","\u003Cp>This module adds a Up2pay e-Transactions Payment Gateway to your Installation of WooCommerce.\u003C\u002Fp>\n\u003Cp>Up2pay e-Transactions is a Payment Services Provider in Europe, part of the Crédit Agricole Bank.\u003C\u002Fp>\n\u003Cp>plugin actions in wordpress:\u003C\u002Fp>\n\u003Cp>this plugin offers an admin panel from the order section to the settings of Woocommerce.\u003Cbr \u002F>\nit adds payment information to the orders details and changes the status of orders (upon reception of an IPN, see below.) and adds payment means on the checkout page.\u003C\u002Fp>\n\u003Cp>This plugin takes information from the order and creates a form containing the details of the payment to be made, including parameters configured in the admin panel of the module that identify the mechant.\u003C\u002Fp>\n\u003Cp>The plugin checks for availability of the Up2pay e-Transactions platform, through a call to our servers.\u003Cbr \u002F>\nIt then submits with javascript the form to the first available server.\u003C\u002Fp>\n\u003Cp>the customer is then presented with a payment page, hosted on the Up2pay e-Transactions Platform (urls above).\u003C\u002Fp>\n\u003Cp>The Up2pay e-Transactions Platform sends an Instant Payment Notification (IPN) to the server when the customer actually made the payment, indicating to the merchant the status of the payment.\u003C\u002Fp>\n\u003Cp>the plugin generates a url that can catch the IPN call from Up2pay e-Transactions’s server, filtering incoming calls to the Up2pay e-Transactions IP address.\u003C\u002Fp>\n\u003Cp>if payment is successfull, then the plugin validates the order though woocommerce.\u003C\u002Fp>\n","This plugin is a Up2pay e-Transactions payment gateway for WooCommerce 4.x",4000,77773,46,13,"2025-05-19T13:31:00.000Z","6.8.6","5.0.0","",[19,53,54,22,23],"orders","payment","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fe-transactions-wc.3.0.9.zip",92,{"slug":58,"name":59,"version":60,"author":61,"author_profile":62,"description":63,"short_description":64,"active_installs":65,"downloaded":66,"rating":26,"num_ratings":26,"last_updated":67,"tested_up_to":15,"requires_at_least":68,"requires_php":69,"tags":70,"homepage":51,"download_link":73,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"hyperpay-gateways","HyperPay Payments","6.4.0","HyperPay","https:\u002F\u002Fprofiles.wordpress.org\u002Fhyperpayproducts\u002F","\u003Cp>Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.\u003Cbr \u002F>\nto be able to use this plugin, you should be one of HyperPay’s customers.\u003Cbr \u002F>\nvisit https:\u002F\u002Fhyperpay.com for more information.\u003C\u002Fp>\n\u003Cp>The data extracted is quite sensitive and contains information that may be used to check the vulnerability of your WordPress site. Be wary of you share this data with.\u003C\u002Fp>\n\u003Ch3>Compatibility\u003C\u002Fh3>\n\u003Cp>The plugin has been tested with\u003Cbr \u002F>\nWC 8.3.1\u003Cbr \u002F>\nwordpress 6.9\u003Cbr \u002F>\nPHP 7.2\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the Hyperpay API to process payments and check transaction status.\u003Cbr \u002F>\n– Data sent: Payment details, order information, and merchant credentials are sent when processing payments.\u003Cbr \u002F>\n– When: Data is sent when a customer initiates a payment or when the plugin checks payment status.\u003Cbr \u002F>\n– Service: Hyperpay https:\u002F\u002Foppwa.com\u003Cbr \u002F>\n– Terms of Service: https:\u002F\u002Fwww.aciworldwide.com\u002Fterms-of-use\u003Cbr \u002F>\n– Privacy Policy: https:\u002F\u002Fwww.aciworldwide.com\u002Fprivacy-policy\u003C\u002Fp>\n\u003Ch3>Third Party Libraries\u003C\u002Fh3>\n\u003Cp>This plugin includes or depends on the following third-party libraries via Composer. All libraries are licensed under GPL-compatible licenses:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>symfony\u002Fpolyfill-php80\u003C\u002Fstrong> (MIT License)\u003Cbr \u002F>\nhttps:\u002F\u002Fgithub.com\u002Fsymfony\u002Fpolyfill-php80\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>psr\u002Flog\u003C\u002Fstrong> (MIT License)\u003Cbr \u002F>\nhttps:\u002F\u002Fgithub.com\u002Fphp-fig\u002Flog\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>guzzlehttp\u002Fguzzle\u003C\u002Fstrong> (MIT License)\u003Cbr \u002F>\nhttps:\u002F\u002Fgithub.com\u002Fguzzle\u002Fguzzle\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>twig\u002Ftwig\u003C\u002Fstrong> (BSD-3-Clause License)\u003Cbr \u002F>\nhttps:\u002F\u002Fgithub.com\u002Ftwigphp\u002FTwig\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>For details, see each library’s LICENSE file in the \u003Ccode>vendor\u002F\u003C\u002Fcode> directory or their respective repositories.\u003C\u002Fp>\n\u003Ch3>Source Code\u003C\u002Fh3>\n\u003Cp>The uncompressed source code for compiled assets (e.g., JavaScript and CSS) is available in the \u003Ccode>\u002Fsrc\u002Fassets\u002F\u003C\u002Fcode> directory.\u003C\u002Fp>\n\u003Cp>Build tools used:\u003Cbr \u002F>\n– Node.js\u003Cbr \u002F>\n– Webpack\u003C\u002Fp>\n\u003Cp>To build:\u003Cbr \u002F>\n1. Run \u003Ccode>npm install\u003C\u002Fcode>\u003Cbr \u002F>\n2. Run \u003Ccode>npm run build\u003C\u002Fcode>\u003C\u002Fp>\n","Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.",600,15778,"2026-05-18T11:22:00.000Z","5.3","7.1",[19,71,72,22,23],"gate2play","merchant","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhyperpay-gateways.6.4.0.zip",{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":82,"downloaded":83,"rating":11,"num_ratings":13,"last_updated":84,"tested_up_to":85,"requires_at_least":86,"requires_php":17,"tags":87,"homepage":90,"download_link":91,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"borica-payments","BORICA Payments by BORICA AD","3.0.6","BORICA AD","https:\u002F\u002Fprofiles.wordpress.org\u002Fborica\u002F","\u003Cp>BORICA Payments is a WooCommerce payment gateway. It works by redirecting customers to the BORICA payment page where they enter their card details. To use this payment option, you need to have a virtual POS terminal.\u003C\u002Fp>\n","Simple way of receiving debit and credit card payments by virtual POS.",500,5754,"2026-06-16T07:44:00.000Z","7.0.2","6.0",[88,89,19,22,23],"borica","card-payments","https:\u002F\u002F3dsgate-dev.borica.bg\u002Fwordpressplugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fborica-payments.3.0.6.zip",{"slug":93,"name":94,"version":95,"author":40,"author_profile":41,"description":96,"short_description":97,"active_installs":82,"downloaded":98,"rating":99,"num_ratings":100,"last_updated":101,"tested_up_to":15,"requires_at_least":50,"requires_php":51,"tags":102,"homepage":51,"download_link":103,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"paybox-woocommerce-gateway","Paybox WooCommerce Payment Gateway","0.9.9.9","\u003Cp>This module adds a Paybox Payment Gateway to your Installation of WooCommerce.\u003C\u002Fp>\n\u003Cp>Paybox is a Payment Services Provider in Europe, part of the Verifone Group.\u003C\u002Fp>\n\u003Cp>plugin actions in wordpress:\u003C\u002Fp>\n\u003Cp>this plugin offers an admin panel from the order section to the settings of Woocommerce.\u003Cbr \u002F>\nit adds payment information to the orders details and changes the status of orders (upon reception of an IPN, see below.) and adds payment means on the checkout page.\u003C\u002Fp>\n\u003Cp>This plugin takes information from the order and creates a form containing the details of the payment to be made, including parameters configured in the admin panel of the module that identify the mechant.\u003C\u002Fp>\n\u003Cp>The plugin checks for availability of the Paybox platform, through a call to our servers.\u003Cbr \u002F>\nIt then submits with javascript the form to the first available server.\u003C\u002Fp>\n\u003Cp>the customer is then presented with a payment page, hosted on the Paybox Platform (urls above).\u003C\u002Fp>\n\u003Cp>The Paybox Platform sends an Instant Payment Notification (IPN) to the server when the customer actually made the payment, indicating to the merchant the status of the payment.\u003C\u002Fp>\n\u003Cp>the plugin generates a url that can catch the IPN call from Paybox’s server, filtering incoming calls to the Paybox IP address.\u003C\u002Fp>\n\u003Cp>if payment is successfull, then the plugin validates the order though woocommerce.\u003C\u002Fp>\n","This plugin is a Paybox payment gateway for WooCommerce 4.x",23281,60,4,"2026-03-17T09:56:00.000Z",[19,53,54,22,23],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpaybox-woocommerce-gateway.0.9.9.9.zip",{"slug":105,"name":106,"version":107,"author":108,"author_profile":109,"description":110,"short_description":111,"active_installs":112,"downloaded":113,"rating":32,"num_ratings":114,"last_updated":115,"tested_up_to":15,"requires_at_least":116,"requires_php":17,"tags":117,"homepage":119,"download_link":120,"security_score":11,"vuln_count":26,"unpatched_count":26,"last_vuln_date":27,"fetched_at":28},"kueskipay-gateway","KueskiPay Gateway","2.4.1","kueski","https:\u002F\u002Fprofiles.wordpress.org\u002Fedgarnomesque\u002F","\u003Cp>Choose how many fortnights to pay with Kueski Pay\u003C\u002Fp>\n\u003Ch3>Requirements\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>WordPress 6.2 or newer.\u003C\u002Fli>\n\u003Cli>WooCommerce 7.6 or newer.\u003C\u002Fli>\n\u003Cli>PHP 7.4 or newer is recommended.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy Notices\u003C\u002Fh3>\n\u003Cp>This plugin connects to a third-party services to perform its functions. Below are the circunstances under wich these connections are made:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>CDN Service for Promotional Widgets\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service Name:\u003C\u002Fstrong> KueskiPay CDN\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Description:\u003C\u002Fstrong> This plugin uses the CDN service at https:\u002F\u002Fcdn.kueskipay.com\u002F to display promotional widgets on the product and cart pages in WooCommerce.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> The following data is sent to this service via GET request:\n\u003Cul>\n\u003Cli>\u003Cstrong>Authorization:\u003C\u002Fstrong> The public key provided at the time of integration.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Integration:\u003C\u002Fstrong> The platform being integrated, in this case, WooCommerce.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Version:\u003C\u002Fstrong> The current version of this plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sandbox:\u003C\u002Fstrong> Indicates whether the current environment is sandbox or production.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Service URL:\u003C\u002Fstrong> https:\u002F\u002Fcdn.kueskipay.com\u002Fwidgets.js\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Example URL:\u003C\u002Fstrong> https:\u002F\u002Fcdn.kueskipay.com\u002Fwidgets.js?authorization=[public_key]&integration=woocommerce&version=[plugin_version]&sandbox[true\u002Ffalse]\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Files Involved:\u003C\u002Fstrong> public\u002Fclass-wc-kuesku-gategay-public.php (Line 227)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Use and Policy:\u003C\u002Fstrong> https:\u002F\u002Fpreguntas.frecuentes.kueski.com\u002Fhc\u002Fes\u002Farticles\u002F12385599806747-PRIVACY-NOTICE-FOR-THIRD-PARTIES-AND-COMMERCIAL-ALLIES-OF-KUESKI-SAPI-DE-CV-SOFOM-ENR\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Payment Order Creation and Management\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service Name:\u003C\u002Fstrong> KueskiPay Payment API\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Description:\u003C\u002Fstrong> This plugin uses the following services to create and manage payment orders:\n\u003Cul>\n\u003Cli>\u003Cstrong>Sandbox:\u003C\u002Fstrong> https:\u002F\u002Fwoocommerce-middleware-go.staging-pay.kueski.codes\u002Fapi\u002Fv1\u002Forder\u002Fcreate\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Production:\u003C\u002Fstrong> https:\u002F\u002Fwoocommerce-middleware-go.production-pay.kueski.com\u002Fapi\u002Fv1\u002Forder\u002Fcreate\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Usage:\u003C\u002Fstrong> The plugin sends the current cart order details to create an order and then redirects the user to the service site to complete their payment.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong> The following data is sent to this service:\n\u003Cul>\n\u003Cli>\u003Cstrong>Order Description\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order Amounts:\u003C\u002Fstrong> total, shipping, discounts and taxes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order Items:\u003C\u002Fstrong> Details of each order item.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shipping Address:\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Billing Address:\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Files Involved:\u003C\u002Fstrong> includes\u002Fclass-wc-kueski-gateway-api.php (Lines 57, 92, 151, 221)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Use and Privacy Policy:\u003C\u002Fstrong> https:\u002F\u002Fpreguntas.frecuentes.kueski.com\u002Fhc\u002Fes\u002Farticles\u002F12385430001563-Aviso-de-privacidad-integral-para-clientes-y-usuarios-de-Kueski-S-A-P-I-de-C-V-SOFOM-E-N-R\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Fol>\n","Add Kueski gateway to buy now and pay later on your store.",300,4272,2,"2026-01-19T17:17:00.000Z","6.2",[19,118,108,22,23],"ecommerce","https:\u002F\u002Fwww.kueskipay.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fkueskipay-gateway.2.4.1.zip",{"attackSurface":122,"codeSignals":167,"taintFlows":183,"riskAssessment":232,"analyzedAt":245},{"hooks":123,"ajaxHandlers":163,"restRoutes":164,"shortcodes":165,"cronEvents":166,"entryPointCount":26,"unprotectedCount":26},[124,130,134,138,143,147,151,152,156,160],{"type":125,"name":126,"callback":127,"file":128,"line":129},"action","wp_enqueue_scripts","payment_scripts","includes\\class-monnify-official.php",118,{"type":125,"name":131,"callback":132,"file":128,"line":133},"woocommerce_available_payment_gateways","add_gateway_to_checkout",119,{"type":125,"name":135,"callback":136,"file":128,"line":137},"woocommerce_api_wc_monnify_gateway","handle_webhook",121,{"type":125,"name":139,"callback":140,"file":141,"line":142},"admin_init","monnify_validate_installed_woocommerce","monnify-official.php",25,{"type":144,"name":145,"callback":146,"file":141,"line":32},"filter","woocommerce_payment_gateways","monnify_add_gateway_class",{"type":125,"name":148,"callback":149,"file":141,"line":150},"admin_notices","monnify_woocommerce_notice",76,{"type":125,"name":139,"callback":140,"file":141,"line":33},{"type":125,"name":153,"callback":154,"file":141,"line":155},"plugins_loaded","woo_monnify_init_gateway_class",102,{"type":125,"name":157,"callback":158,"file":141,"line":159},"woocommerce_blocks_loaded","monnify_register_blocks_support",114,{"type":125,"name":161,"callback":162,"file":141,"line":133},"woocommerce_blocks_payment_method_type_registration","closure",[],[],[],[],{"dangerousFunctions":168,"sqlUsage":169,"outputEscaping":171,"fileOperations":13,"externalRequests":114,"nonceChecks":13,"capabilityChecks":26,"bundledLibraries":182},[],{"prepared":26,"raw":26,"locations":170},[],{"escaped":172,"rawEcho":173,"locations":174},17,3,[175,178,180],{"file":128,"line":176,"context":177},364,"raw output",{"file":128,"line":179,"context":177},366,{"file":141,"line":181,"context":177},48,[],[184,219],{"entryPoint":185,"graph":186,"unsanitizedCount":13,"severity":218},"monnify_trans_verify_payment (includes\\class-monnify-official.php:519)",{"nodes":187,"edges":212},[188,193,199,203,207],{"id":189,"type":190,"label":191,"file":128,"line":192},"n0","source","$_GET (x2)",538,{"id":194,"type":195,"label":196,"file":128,"line":197,"wp_function":198},"n1","sink","wp_redirect() [Open Redirect]",559,"wp_redirect",{"id":200,"type":190,"label":201,"file":128,"line":202},"n2","$_GET",570,{"id":204,"type":205,"label":206,"file":128,"line":202},"n3","transform","→ verify_monnify_transaction()",{"id":208,"type":195,"label":209,"file":128,"line":210,"wp_function":211},"n4","wp_remote_get() [SSRF]",649,"wp_remote_get",[213,215,217],{"from":189,"to":194,"sanitized":214},true,{"from":200,"to":204,"sanitized":216},false,{"from":204,"to":208,"sanitized":216},"medium",{"entryPoint":220,"graph":221,"unsanitizedCount":13,"severity":218},"\u003Cclass-monnify-official> (includes\\class-monnify-official.php:0)",{"nodes":222,"edges":228},[223,224,225,226,227],{"id":189,"type":190,"label":191,"file":128,"line":192},{"id":194,"type":195,"label":196,"file":128,"line":197,"wp_function":198},{"id":200,"type":190,"label":201,"file":128,"line":202},{"id":204,"type":205,"label":206,"file":128,"line":202},{"id":208,"type":195,"label":209,"file":128,"line":210,"wp_function":211},[229,230,231],{"from":189,"to":194,"sanitized":214},{"from":200,"to":204,"sanitized":216},{"from":204,"to":208,"sanitized":216},{"summary":233,"deductions":234},"The \"monnify-official\" v1.0.3 plugin exhibits a generally good security posture based on the provided static analysis.  The plugin demonstrates strong adherence to secure coding practices by not exposing any AJAX handlers or REST API routes without proper authentication checks, and it avoids using shortcodes or cron events.  The code also shows positive signs with 100% of SQL queries utilizing prepared statements, which is a critical defense against SQL injection.  However, a notable concern arises from the taint analysis, which identified 2 flows with unsanitized paths. While no critical or high severity issues were flagged in the taint analysis, these unsanitized paths still represent potential entry points for malicious data to be processed without adequate validation, which could lead to unexpected behavior or further vulnerabilities if exploited in conjunction with other factors.\n\nThe plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of stable and relatively secure development.  Despite the positive history, the presence of unsanitized paths in the taint analysis warrants attention.  The plugin's strengths lie in its minimal attack surface and secure handling of database interactions. The primary weakness, as indicated by the taint analysis, is the need for better sanitization of input paths.  Overall, the plugin is likely secure for general use, but the identified taint flows are a point of concern that should be addressed to further harden its security.",[235,238,241,243],{"reason":236,"points":237},"Unsanitized paths in taint analysis",8,{"reason":239,"points":240},"Low percentage of properly escaped output",5,{"reason":242,"points":114},"File operations detected",{"reason":244,"points":114},"External HTTP requests detected","2026-03-16T21:31:57.645Z",{"wat":247,"direct":258},{"assetPaths":248,"generatorPatterns":252,"scriptPaths":253,"versionParams":254},[249,250,251],"\u002Fwp-content\u002Fplugins\u002Fmonnify-official\u002Fassets\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fmonnify-official\u002Fassets\u002Fjs\u002Fmain.js","\u002Fwp-content\u002Fplugins\u002Fmonnify-official\u002Fassets\u002Fjs\u002Fcheckout.js",[],[250,251],[255,256,257],"monnify-official\u002Fassets\u002Fcss\u002Fstyle.css?ver=","monnify-official\u002Fassets\u002Fjs\u002Fmain.js?ver=","monnify-official\u002Fassets\u002Fjs\u002Fcheckout.js?ver=",{"cssClasses":259,"htmlComments":261,"htmlAttributes":262,"restEndpoints":266,"jsGlobals":267,"shortcodeOutput":268},[260],"monnify-payment-gateway",[],[263,264,265],"data-monnify-public-key","data-monnify-secret-key","data-monnify-contract-code",[],[20],[],{"error":214,"url":270,"statusCode":271,"statusMessage":272,"message":272},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fmonnify-official\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":173,"versions":274},[275,280,287],{"version":6,"download_url":25,"svn_tag_url":276,"released_at":27,"has_diff":216,"diff_files_changed":277,"diff_lines":27,"trac_diff_url":278,"vulnerabilities":279,"is_current":214},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmonnify-official\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmonnify-official%2Ftags%2F1.0.2&new_path=%2Fmonnify-official%2Ftags%2F1.0.3",[],{"version":281,"download_url":282,"svn_tag_url":283,"released_at":27,"has_diff":216,"diff_files_changed":284,"diff_lines":27,"trac_diff_url":285,"vulnerabilities":286,"is_current":216},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmonnify-official.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmonnify-official\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmonnify-official%2Ftags%2F1.0.1&new_path=%2Fmonnify-official%2Ftags%2F1.0.2",[],{"version":288,"download_url":289,"svn_tag_url":290,"released_at":27,"has_diff":216,"diff_files_changed":291,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":292,"is_current":216},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmonnify-official.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmonnify-official\u002Ftags\u002F1.0.1\u002F",[],[]]