My-CoolPay – Payment gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/my-coolpay-payment-gateway-for-woocommerce

The best modern and secure payment plugin for WooCommerce in Cameroon accepting Orange Money, MTN Mobile Money, VISA, MasterCard and My-CoolPay Wallet

100 active installs v1.6.2 PHP 7.1+ WP 5.5.1+ Updated Oct 16, 2025
cameroonmobile-moneymy-coolpaymycoolpaypayment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My-CoolPay – Payment gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

My-CoolPay – Payment gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The plugin "my-coolpay-payment-gateway-for-woocommerce" v1.6.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a history of unpatched vulnerabilities suggests a well-maintained and secure codebase. The static analysis further supports this, showing a very limited attack surface with no reported AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, no unprotected entry points. The code also demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and not performing file operations or external HTTP requests that could be easily exploited.

However, a significant concern arises from the complete lack of output escaping. With two identified output points and 0% being properly escaped, this represents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the WordPress frontend through user-controllable data that is not properly sanitized before being displayed. The absence of nonce and capability checks, while not directly linked to an exposed attack surface in this analysis, could become a weakness if new entry points were ever introduced. The lack of taint analysis data is also a limitation, as it prevents a deeper understanding of how data flows within the plugin and if potentially malicious data could be mishandled, even if not immediately obvious from the static code structure.

In conclusion, while the plugin is commendably free of known vulnerabilities and maintains a minimal attack surface, the unescaped output is a critical oversight that demands immediate attention. This vulnerability significantly undermines the plugin's otherwise good security practices. Addressing the output escaping issue should be the highest priority, followed by strengthening authentication checks if any new entry points are ever developed. The absence of taint flow analysis suggests that a more in-depth review might be beneficial to ensure data handling is robust.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

My-CoolPay – Payment gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

My-CoolPay – Payment gateway for WooCommerce Release Timeline

v1.6.2Current
v1.6.1
v1.6.0
v1.5.0
v1.4.1
v1.4.0
v1.3.3
v1.3.2
v1.3.1
v1.3
v1.2.1
v1.2
v1.1
v1.0.7
Code Analysis
Analyzed Mar 16, 2026

My-CoolPay – Payment gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

My-CoolPay – Payment gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionrest_api_initinclude\mycoolpay_callback.php:21
filtermanage_edit-shop_order_columnsinclude\mycoolpay_hooks.php:20
actionmanage_shop_order_posts_custom_columninclude\mycoolpay_hooks.php:34
filterwoocommerce_shop_order_search_fieldsinclude\mycoolpay_hooks.php:46
actionwoocommerce_payment_completeinclude\mycoolpay_hooks.php:61
filtermanage_edit-shop_order_columnsinclude\mycoolpay_update_wc_admin_order_list.php:20
actionmanage_shop_order_posts_custom_columninclude\mycoolpay_update_wc_admin_order_list.php:34
filterwoocommerce_shop_order_search_fieldsinclude\mycoolpay_update_wc_admin_order_list.php:46
filterwoocommerce_payment_gatewaysmy-coolpay-woocommerce-gateway.php:80
actionplugins_loadedmy-coolpay-woocommerce-gateway.php:93
actionwoocommerce_blocks_payment_method_type_registrationmy-coolpay-woocommerce-gateway.php:104
actionwoocommerce_blocks_loadedmy-coolpay-woocommerce-gateway.php:114
actionbefore_woocommerce_initmy-coolpay-woocommerce-gateway.php:116
Maintenance & Trust

My-CoolPay – Payment gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 16, 2025
PHP min version7.1
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

My-CoolPay – Payment gateway for WooCommerce Developer Profile

My-CoolPay

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect My-CoolPay – Payment gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-coolpay-payment-gateway-for-woocommerce/assets/css/mycoolpay.css/wp-content/plugins/my-coolpay-payment-gateway-for-woocommerce/assets/js/mycoolpay.js
Script Paths
/wp-content/plugins/my-coolpay-payment-gateway-for-woocommerce/assets/js/mycoolpay.js
Version Parameters
my-coolpay-payment-gateway-for-woocommerce/assets/css/mycoolpay.css?ver=my-coolpay-payment-gateway-for-woocommerce/assets/js/mycoolpay.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/callback/
FAQ

Frequently Asked Questions about My-CoolPay – Payment gateway for WooCommerce