Payment Gateway for Monnify on WooCommerce Security & Risk Analysis

wordpress.org/plugins/monnify-payment-gateway

Payment Gateway for Monnify on WooCommerce allows you to accept online payments from local and international customers

60 active installs v1.0.10 PHP 5.6+ WP 4.7+ Updated May 6, 2026
adeleye-pluginsmonnifypayment-gatewayvervewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for Monnify on WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway for Monnify on WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The Monnify Payment Gateway plugin version 1.0.9 exhibits a generally good security posture with no recorded vulnerabilities or known CVEs. The static analysis reveals a clean codebase with no dangerous functions, file operations, or SQL queries that do not use prepared statements. Furthermore, there are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting the plugin's attack surface. The absence of these common entry points suggests a proactive approach to security by the developers.

However, there are areas for concern. The taint analysis indicates two flows with unsanitized paths, which, while not classified as critical or high severity in this instance, represent a potential risk. The output escaping is also a weakness, with only 54% of outputs being properly escaped, leaving room for cross-site scripting (XSS) vulnerabilities if malicious data is processed. The lack of nonce and capability checks on any potential entry points, although the static analysis reports zero entry points, is a general concern if any future functionality is added without these crucial security measures. The two external HTTP requests also warrant scrutiny to ensure they are handled securely and do not expose sensitive information or introduce supply chain risks.

In conclusion, while the plugin benefits from a minimal attack surface and a clean history, the presence of unsanitized paths and insufficient output escaping indicates that developers should prioritize addressing these issues. The lack of any identified entry points is a significant strength, but vigilance is required for future development to maintain this secure state. Addressing the identified taint flows and improving output escaping would significantly bolster the plugin's overall security.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Insufficient output escaping (54% properly escaped)
  • External HTTP requests present (2)
  • No nonce checks on any entry points
  • No capability checks on any entry points
Vulnerabilities
None known

Payment Gateway for Monnify on WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Payment Gateway for Monnify on WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for Monnify on WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

54% escaped13 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
monnify_verify_payment (includes\class-wc-gateway-monnify.php:333)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payment Gateway for Monnify on WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionwoocommerce_rest_checkout_process_payment_with_contextincludes\class-wc-gateway-monnify-blocks-support.php:24
actionwc_gateway_monnify_process_payment_errorincludes\class-wc-gateway-monnify-blocks-support.php:102
actionwp_enqueue_scriptsincludes\class-wc-gateway-monnify.php:158
actionwoocommerce_available_payment_gatewaysincludes\class-wc-gateway-monnify.php:159
actionadmin_enqueue_scriptsincludes\class-wc-gateway-monnify.php:160
actionwoocommerce_api_wc_monnify_payment_gatewayincludes\class-wc-gateway-monnify.php:162
actionplugins_loadedwc-monnify-payment-gateway.php:24
actionadmin_noticeswc-monnify-payment-gateway.php:33
filterwoocommerce_payment_gatewayswc-monnify-payment-gateway.php:38
actionbefore_woocommerce_initwc-monnify-payment-gateway.php:89
actionwoocommerce_blocks_payment_method_type_registrationwc-monnify-payment-gateway.php:110
actionwoocommerce_blocks_loadedwc-monnify-payment-gateway.php:122
Maintenance & Trust

Payment Gateway for Monnify on WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMay 6, 2026
PHP min version5.6
Downloads3K

Community Trust

Rating20/100
Number of ratings1
Active installs60
Developer Profile

Payment Gateway for Monnify on WooCommerce Developer Profile

Adeleye Ayodeji

3 plugins · 60 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for Monnify on WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/monnify-payment-gateway/assets/css/monnify.css/wp-content/plugins/monnify-payment-gateway/assets/js/monnify.js
Script Paths
/wp-content/plugins/monnify-payment-gateway/assets/js/monnify.js
Version Parameters
monnify-payment-gateway/assets/css/monnify.css?ver=monnify-payment-gateway/assets/js/monnify.js?ver=

HTML / DOM Fingerprints

CSS Classes
monnify-payment-method-description
HTML Comments
<!-- Monnify Payment test mode is still enabled, Click here to disable it when you want to start accepting live payment on your site.
JS Globals
wc_monnify_params
FAQ

Frequently Asked Questions about Payment Gateway for Monnify on WooCommerce