
OrendaPay Security & Risk Analysis
wordpress.org/plugins/orendapayGenerate bank billet and credit or debit card transactions at transparency Checkout of your Woocommerce from WordPress using Orenda Pay.
Is OrendaPay Safe to Use in 2026?
Generally Safe
Score 92/100OrendaPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The orendapay v4.3.1 plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the plugin does not appear to use dangerous functions. All SQL queries are correctly prepared, which is a strong security practice. However, significant concerns arise from the static analysis. A concerningly low 8% of output is properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests without apparent authorization checks or sanitization on paths is a notable risk, as indicated by the taint analysis showing all flows with unsanitized paths. Furthermore, the complete lack of nonce and capability checks on entry points is a critical oversight, especially given the presence of file operations and external requests that could be triggered by unauthenticated users.
Key Concerns
- Output escaping is severely lacking
- Taint analysis shows unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
- File operations present without auth checks
- External HTTP requests present without auth checks
OrendaPay Security Vulnerabilities
OrendaPay Release Timeline
OrendaPay Code Analysis
Output Escaping
Data Flow Analysis
OrendaPay Attack Surface
WordPress Hooks 13
Maintenance & Trust
OrendaPay Maintenance & Trust
Maintenance Signals
Community Trust
OrendaPay Alternatives
PagHiper Boleto e PIX para WooCommerce
woo-boleto-paghiper
Ofereça a seus clientes pagamento boleto bancário com a PagHiper. Fácil, prático e rapido!
iPag Pagamentos Digitais
ipag-woocommerce
Facilite pagamentos online com segurança e rapidez, integrando sua loja ao nosso gateway e PSP.
Pagou – Payments for WooCommerce
pagou-payments-for-woocommerce
Pagamentos via PIX e boletos bancários no WooCommerce.
Global Pays – Payments for WooCommerce
global-pays-payments-for-woocommerce
PIX, Boleto and credit card payments in WooCommerce.
Z4Money para WooCommerce
wc-z4money
O Plugin oficial Z4Money para WooCommerce.
OrendaPay Developer Profile
1 plugin · 10 total installs
How We Detect OrendaPay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orendapay/assets/css/orendapay-checkout.css/wp-content/plugins/orendapay/assets/js/orendapay-checkout.js/wp-content/plugins/orendapay/assets/js/orendapay-checkout.jsorendapay/assets/css/orendapay-checkout.css?ver=orendapay/assets/js/orendapay-checkout.js?ver=HTML / DOM Fingerprints
orendapay-checkout-wrapOrendaPayCheckout/wp-json/orendapay/v1/process_payment