Moolre Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/moolre-payment-gateway

Moolre for WooCommerce allows your store in Ghana to Nigeria to accept secure payments from multiple local and global payment channels.

30 active installs v1.2.4 PHP 7.4+ WP 6.2+ Updated Apr 2, 2025
atghanamoolremtnpayment
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Moolre Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Moolre Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "moolre-payment-gateway" plugin version 1.2.4 exhibits a strong adherence to WordPress security best practices, particularly in its approach to handling SQL queries and its limited attack surface. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events, especially without authentication checks, significantly reduces the potential entry points for attackers. Furthermore, the code analysis shows no dangerous functions, no file operations, and a respectable output escaping rate of 71%. The presence of nonce and capability checks, along with 100% prepared statement usage for SQL queries, indicates a robust defense against common vulnerabilities like SQL injection and unauthorized access.

While the static analysis reveals no critical or high-severity issues in taint flows, and the vulnerability history is clean with zero recorded CVEs, there are minor areas for attention. The presence of two external HTTP requests, though not inherently a vulnerability, represents a potential attack vector if the remote endpoints are compromised or if the requests are not handled with sufficient sanitization of incoming data. The 71% output escaping rate, while generally good, means that 29% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities in specific scenarios if user-controlled data is involved in those unescaped outputs.

Overall, the plugin demonstrates a good security posture with minimal immediate risks. The lack of known vulnerabilities and a well-controlled attack surface are significant strengths. The primary areas for improvement lie in ensuring all outputs are properly escaped and carefully reviewing the security implications of the external HTTP requests. The absence of any taint analysis results also suggests that either the taint analysis tooling did not find any flows or the code is structured in a way that such flows are not readily apparent, which is a positive sign. The plugin appears to be developed with security in mind, but continued vigilance and attention to detail in all aspects of code can further enhance its security.

Key Concerns

  • Unescaped output present
Vulnerabilities
None known

Moolre Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Moolre Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
10 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

71% escaped14 total outputs
Attack Surface

Moolre Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticesincludes\class-mpwp-moolre-payment-gateway.php:153
actionwoocommerce_api_mpwp_moolre_payment_gatewayincludes\class-mpwp-moolre-payment-gateway.php:159
actionwoocommerce_api_moolre_gatewayincludes\class-mpwp-moolre-payment-gateway.php:162
actionbefore_woocommerce_initmoolre-commerce.php:27
actionbefore_woocommerce_initmoolre-commerce.php:46
actionwoocommerce_blocks_loadedmoolre-commerce.php:50
actionwoocommerce_blocks_payment_method_type_registrationmoolre-commerce.php:66
actionadmin_noticesmoolre-commerce.php:118
actionplugins_loadedmoolre-commerce.php:123
filterwoocommerce_payment_gatewaysmoolre-commerce.php:136
Maintenance & Trust

Moolre Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 2, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Moolre Payment Gateway for WooCommerce Developer Profile

moolre

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Moolre Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/moolre-payment-gateway/assets/css/mpwp-styles.css/wp-content/plugins/moolre-payment-gateway/assets/js/mpwp-scripts.js
Version Parameters
mpwp-scripts.js?ver=mpwp-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
mpwp-moolre-payment-gateway-wrapper
HTML Comments
<!-- BEGIN Moolre Payment Gateway --><!-- END Moolre Payment Gateway -->
Data Attributes
data-mpwp-public-keydata-mpwp-environment
JS Globals
mpwp_payment_gateway_blocks_integration
FAQ

Frequently Asked Questions about Moolre Payment Gateway for WooCommerce