OrendaPay Security & Risk Analysis

wordpress.org/plugins/orendapay

Generate bank billet and credit or debit card transactions at transparency Checkout of your Woocommerce from WordPress using Orenda Pay.

10 active installs v4.3.1 PHP 7.4+ WP 5.5.2+ Updated Sep 14, 2024
boletocheckoutorendapaypagamentopix
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OrendaPay Safe to Use in 2026?

Generally Safe

Score 92/100

OrendaPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The orendapay v4.3.1 plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the plugin does not appear to use dangerous functions. All SQL queries are correctly prepared, which is a strong security practice. However, significant concerns arise from the static analysis. A concerningly low 8% of output is properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests without apparent authorization checks or sanitization on paths is a notable risk, as indicated by the taint analysis showing all flows with unsanitized paths. Furthermore, the complete lack of nonce and capability checks on entry points is a critical oversight, especially given the presence of file operations and external requests that could be triggered by unauthenticated users.

Key Concerns

  • Output escaping is severely lacking
  • Taint analysis shows unsanitized paths
  • No nonce checks on entry points
  • No capability checks on entry points
  • File operations present without auth checks
  • External HTTP requests present without auth checks
Vulnerabilities
None known

OrendaPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

OrendaPay Release Timeline

v5.9
Code Analysis
Analyzed Mar 17, 2026

OrendaPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

8% escaped13 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
orendapay_class_init (woo-orendapay.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

OrendaPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterwoocommerce_payment_gatewayswoo-orendapay.php:22
actionplugins_loadedwoo-orendapay.php:34
actionwoocommerce_api_orendapay_webhookwoo-orendapay.php:104
actionwoocommerce_orendapay_webhook_notificationwoo-orendapay.php:105
actionwp_enqueue_scriptswoo-orendapay.php:108
actionwoocommerce_email_after_order_tablewoo-orendapay.php:111
actionwoocommerce_order_details_after_order_tablewoo-orendapay.php:112
actionadmin_noticeswoo-orendapay.php:967
actionadmin_noticeswoo-orendapay.php:973
actionadmin_noticeswoo-orendapay.php:979
actionadmin_noticeswoo-orendapay.php:985
actionadmin_noticeswoo-orendapay.php:990
actionadmin_noticeswoo-orendapay.php:995
Maintenance & Trust

OrendaPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 14, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

OrendaPay Developer Profile

orendapay

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OrendaPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orendapay/assets/css/orendapay-checkout.css/wp-content/plugins/orendapay/assets/js/orendapay-checkout.js
Script Paths
/wp-content/plugins/orendapay/assets/js/orendapay-checkout.js
Version Parameters
orendapay/assets/css/orendapay-checkout.css?ver=orendapay/assets/js/orendapay-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
orendapay-checkout-wrap
JS Globals
OrendaPayCheckout
REST Endpoints
/wp-json/orendapay/v1/process_payment
FAQ

Frequently Asked Questions about OrendaPay