Monobank WP Payment Security & Risk Analysis

wordpress.org/plugins/monopay

Офіційний модуль від monobank для підключення інтернет-еквайрингу.

1K active installs v3.2.1 PHP 7.4+ WP 6.2+ Updated Sep 24, 2024
cashiermonopaymentsrouting
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Monobank WP Payment Safe to Use in 2026?

Generally Safe

Score 92/100

Monobank WP Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis, the "monopay" plugin v3.2.1 appears to have a strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks indicates a minimal attack surface. Furthermore, the consistent use of prepared statements for SQL queries is a significant strength. The plugin also demonstrates good practices with the presence of nonce and capability checks, although the total number is relatively low.

However, there are areas for potential concern. A notable weakness is the output escaping, with only 60% of outputs being properly escaped, leaving 40% potentially vulnerable to cross-site scripting (XSS) attacks. While no critical or high severity taint flows were identified, the lack of taint analysis data means we cannot definitively rule out such vulnerabilities. The plugin's vulnerability history being completely clear is a positive sign, suggesting a commitment to security or a lack of prior discoveries. Despite the low number of file operations and external HTTP requests, these can still be vectors for compromise if not handled with extreme care.

In conclusion, "monopay" v3.2.1 exhibits good foundational security practices, particularly in its handling of the attack surface and SQL queries. The primary weakness lies in the insufficient output escaping, which presents a tangible risk. The lack of historical vulnerabilities is reassuring, but the absence of comprehensive taint analysis leaves a gap in the overall security assurance. Addressing the output escaping issues would significantly improve its security profile.

Key Concerns

  • Output escaping only 60% complete
Vulnerabilities
None known

Monobank WP Payment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Monobank WP Payment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
6 escaped
Nonce Checks
1
Capability Checks
3
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

60% escaped10 total outputs
Attack Surface

Monobank WP Payment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionwoocommerce_api_mono_gatewayincludes\class-wc-mono-gateway.php:66
actionwoocommerce_admin_order_totals_after_totalincludes\class-wc-mono-gateway.php:67
actionadd_meta_boxesincludes\class-wc-mono-gateway.php:69
actionwoocommerce_api_mono_finalize_holdincludes\class-wc-mono-gateway.php:70
actionwoocommerce_api_mono_cancel_holdincludes\class-wc-mono-gateway.php:71
actionwoocommerce_api_mono_refreshincludes\class-wc-mono-gateway.php:72
actionwoocommerce_thankyouincludes\class-wc-mono-gateway.php:73
actionplugins_loadedmonopay.php:23
actionplugins_loadedmonopay.php:25
filterwoocommerce_payment_gatewaysmonopay.php:27
actionwoocommerce_blocks_loadedmonopay.php:29
actionwoocommerce_blocks_payment_method_type_registrationmonopay.php:72
actionwp_enqueue_scriptsmonopay.php:101
Maintenance & Trust

Monobank WP Payment Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedSep 24, 2024
PHP min version7.4
Downloads13K

Community Trust

Rating50/100
Number of ratings8
Active installs1K
Developer Profile

Monobank WP Payment Developer Profile

plata by mono

2 plugins · 1K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Monobank WP Payment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/monopay/assets/css/custom.css

HTML / DOM Fingerprints

Data Attributes
data-key="mono_gateway"
JS Globals
window.mono_data
REST Endpoints
/wp-json/mono_gateway/v1/webhook
FAQ

Frequently Asked Questions about Monobank WP Payment