
Om Dusupay Gateway Woocommerce Security & Risk Analysis
wordpress.org/plugins/om-dusupay-gateway-woocommerceOm Dusupay Gateway Woocommerce By: Siddharth Singh Email:siddharthsingh91@gmail.com Contributors: siddharthsingh91 Donate link: http://www.
Is Om Dusupay Gateway Woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100Om Dusupay Gateway Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "om-dusupay-gateway-woocommerce" v01.01.03 presents a concerning security posture despite the absence of known vulnerabilities and a clean history. The static analysis reveals a significant issue with output escaping, where 100% of the 11 identified output points are not properly escaped. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website through user-generated content or data processed by the plugin. Additionally, the taint analysis shows 3 flows with unsanitized paths, suggesting potential risks if user input is not adequately validated and cleaned before being processed or displayed, though no critical or high severity issues were flagged here. The plugin lacks any explicit capability checks and nonce checks, which are fundamental security mechanisms for protecting against unauthorized actions and request forgery, especially in WordPress environments. While the plugin demonstrates good practices in using prepared statements for SQL queries and has no recorded CVEs, the pervasive lack of output escaping and missing security checks create a substantial attack surface that could be exploited, especially in conjunction with the identified unsanitized taint flows.
Key Concerns
- Output escaping is missing for all outputs
- Taint analysis shows unsanitized paths
- No nonce checks implemented
- No capability checks implemented
Om Dusupay Gateway Woocommerce Security Vulnerabilities
Om Dusupay Gateway Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Om Dusupay Gateway Woocommerce Attack Surface
WordPress Hooks 9
Maintenance & Trust
Om Dusupay Gateway Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Om Dusupay Gateway Woocommerce Alternatives
No alternatives data available yet.
Om Dusupay Gateway Woocommerce Developer Profile
5 plugins · 40 total installs
How We Detect Om Dusupay Gateway Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/om-dusupay-gateway-woocommerce/img/logo.png/wp-content/plugins/om-dusupay-gateway-woocommerce/img/dusupaybtn6.pngHTML / DOM Fingerprints
name="dusupay_merchantId"name="dusupay_amount"name="dusupay_currency"name="dusupay_itemId"name="dusupay_itemName"name="dusupay_transactionReference"+6 more<form method="post" action="https://www.dusupay.com/dusu_payments/dusupay" target="_self"><input type="hidden" name="dusupay_merchantId" value="<input type="hidden" name="dusupay_amount" value="<input type="hidden" name="dusupay_currency" value="