
Pakasir for WooCommerce Security & Risk Analysis
wordpress.org/plugins/pakasir-for-woocommercePakasir Payment Gateway (QRIS, Virtual Account, etc) for WooComerce. (compatible with Indonesia banks/e-wallets only)
Is Pakasir for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Pakasir for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "pakasir-for-woocommerce" v1.2.4 reveals a generally strong security posture. The plugin exhibits excellent practices by having no unauthenticated AJAX handlers or REST API routes, and all detected SQL queries utilize prepared statements, with all output being properly escaped. The absence of file operations and external HTTP requests further limits potential attack vectors. However, the lack of nonce checks and capability checks across all entry points, despite a small attack surface, presents a notable concern. This means that while the entry points are secured against direct unauthenticated access, authenticated users could potentially trigger functionality without explicit verification of their intent or permissions for specific actions, assuming the single REST API route is the only executable path. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of its security over time. This suggests the developers have a good understanding of secure coding practices. The primary weakness lies in the reliance on WordPress's inherent authentication without explicit re-verification at the plugin level for its limited entry points. Overall, the plugin is well-coded with minimal identified risks, but the absence of specific WordPress security checks could be exploited if the single REST API route has sensitive functionality.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
Pakasir for WooCommerce Security Vulnerabilities
Pakasir for WooCommerce Code Analysis
Pakasir for WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 4
Maintenance & Trust
Pakasir for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Pakasir for WooCommerce Alternatives
Duitku Pop Payment Gateway
duitku-pop-payment-gateway
Do you want the best solution to accept Credit Cards, e-wallet, and Various Bank Transfers on your website? Our Payment Gateway for WooCommerce plugin …
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pakasir for WooCommerce Developer Profile
1 plugin · 60 total installs
How We Detect Pakasir for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pakasir-for-woocommerce/includes/class-wc-gateway-pakasir.php/wp-content/plugins/pakasir-for-woocommerce/includes/class-wc-gateway-blocks-support.php/wp-content/plugins/pakasir-for-woocommerce/pakasir.phppakasir-for-woocommerce/pakasir.php?ver=pakasir-for-woocommerce/includes/class-wc-gateway-pakasir.php?ver=pakasir-for-woocommerce/includes/class-wc-gateway-blocks-support.php?ver=HTML / DOM Fingerprints
/wp-json/pakasir/v1/webhook