
My-CoolPay – Payment gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/my-coolpay-payment-gateway-for-woocommerceThe best modern and secure payment plugin for WooCommerce in Cameroon accepting Orange Money, MTN Mobile Money, VISA, MasterCard and My-CoolPay Wallet
Is My-CoolPay – Payment gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100My-CoolPay – Payment gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "my-coolpay-payment-gateway-for-woocommerce" v1.6.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a history of unpatched vulnerabilities suggests a well-maintained and secure codebase. The static analysis further supports this, showing a very limited attack surface with no reported AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, no unprotected entry points. The code also demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and not performing file operations or external HTTP requests that could be easily exploited.
However, a significant concern arises from the complete lack of output escaping. With two identified output points and 0% being properly escaped, this represents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the WordPress frontend through user-controllable data that is not properly sanitized before being displayed. The absence of nonce and capability checks, while not directly linked to an exposed attack surface in this analysis, could become a weakness if new entry points were ever introduced. The lack of taint analysis data is also a limitation, as it prevents a deeper understanding of how data flows within the plugin and if potentially malicious data could be mishandled, even if not immediately obvious from the static code structure.
In conclusion, while the plugin is commendably free of known vulnerabilities and maintains a minimal attack surface, the unescaped output is a critical oversight that demands immediate attention. This vulnerability significantly undermines the plugin's otherwise good security practices. Addressing the output escaping issue should be the highest priority, followed by strengthening authentication checks if any new entry points are ever developed. The absence of taint flow analysis suggests that a more in-depth review might be beneficial to ensure data handling is robust.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
My-CoolPay – Payment gateway for WooCommerce Security Vulnerabilities
My-CoolPay – Payment gateway for WooCommerce Release Timeline
My-CoolPay – Payment gateway for WooCommerce Code Analysis
Output Escaping
My-CoolPay – Payment gateway for WooCommerce Attack Surface
WordPress Hooks 13
Maintenance & Trust
My-CoolPay – Payment gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
My-CoolPay – Payment gateway for WooCommerce Alternatives
Direct Payments for WooCommerce – Bank Transfer, Mobile Money, Crypto and Peer-to-Peer (P2P) Payments
direct-payments-for-woocommerce
Direct Payments for WooCommerce allows your store to accept instant payments via bank transfers, mobile money, crypto and popular P2P platforms global …
KKiapay WooCommerce Plugin
kkiapay-woocommerce
Accept Mobile money, direct bank and credit card payments with KKiapay
Campay Woocommerce Payment Gateway
campay-api
CamPay is a Fintech service of the company TAKWID
FeexPay
feexpay
A secure plugin to accept Mobile Money and Credit Card payments.
Easypay Mobile Money
easypay-mobile-money
Allow mobile money (MTN,Airtel,M-Sente & Africell Money), Visa & Mastercard payments within your woocommerce stores and wordpress.
My-CoolPay – Payment gateway for WooCommerce Developer Profile
1 plugin · 100 total installs
How We Detect My-CoolPay – Payment gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-coolpay-payment-gateway-for-woocommerce/assets/css/mycoolpay.css/wp-content/plugins/my-coolpay-payment-gateway-for-woocommerce/assets/js/mycoolpay.js/wp-content/plugins/my-coolpay-payment-gateway-for-woocommerce/assets/js/mycoolpay.jsmy-coolpay-payment-gateway-for-woocommerce/assets/css/mycoolpay.css?ver=my-coolpay-payment-gateway-for-woocommerce/assets/js/mycoolpay.js?ver=HTML / DOM Fingerprints
/wp-json/callback/