Nepali Payments for CampTix Security & Risk Analysis

wordpress.org/plugins/nepali-payments-for-camptix

Add Nepali payment gateway support to CampTix for accepting payments in Nepali Rupees (NPR).

0 active installs v1.0.1 PHP + WP 3.5+ Updated Aug 6, 2025
camptixgatewaynepalipayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Nepali Payments for CampTix Safe to Use in 2026?

Generally Safe

Score 100/100

Nepali Payments for CampTix has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'nepali-payments-for-camptix' plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points indicates a limited attack surface. Furthermore, the code demonstrates excellent practices with 100% of SQL queries using prepared statements and all output being properly escaped, which are critical defenses against common web vulnerabilities. The presence of nonce checks and the absence of dangerous functions further bolster its security.

However, the analysis does reveal a couple of areas that warrant attention. While there are no recorded historical vulnerabilities, the plugin makes two external HTTP requests, which could potentially be a vector for supply chain attacks or information leakage if not handled with utmost care and validated rigorously. The complete lack of capability checks is also a concern, as it implies that any user, regardless of their role or permissions, might interact with any functionality the plugin exposes, potentially leading to privilege escalation or unauthorized actions in future iterations or if the attack surface expands.

In conclusion, the plugin is currently very secure due to its minimal attack surface and adherence to secure coding practices for SQL and output handling. The primary weaknesses lie in the potential risks associated with external HTTP requests and the complete absence of capability checks. These are not immediate critical vulnerabilities based on the current data but represent areas for improvement to maintain a robust security profile.

Key Concerns

  • No capability checks implemented
  • Two external HTTP requests made
Vulnerabilities
None known

Nepali Payments for CampTix Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Nepali Payments for CampTix Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
24 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped24 total outputs
Attack Surface

Nepali Payments for CampTix Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actiontemplate_redirectincludes\class-camptix-khalti-payment.php:76
actionplugins_loadednepali-payments-for-camptix.php:50
actioncamptix_load_addonsnepali-payments-for-camptix.php:51
filtercamptix_currenciesnepali-payments-for-camptix.php:52
Maintenance & Trust

Nepali Payments for CampTix Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 6, 2025
PHP min version
Downloads310

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Nepali Payments for CampTix Developer Profile

arunpyasi

2 plugins · 100 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nepali Payments for CampTix

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nepali-payments-for-camptix/js/khalti-redirect.js
Script Paths
/wp-content/plugins/nepali-payments-for-camptix/js/khalti-redirect.js
Version Parameters
nepali-payments-for-camptix/js/khalti-redirect.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Nepali Payments for CampTix