Pakasir for WooCommerce Security & Risk Analysis

wordpress.org/plugins/pakasir-for-woocommerce

Pakasir Payment Gateway (QRIS, Virtual Account, etc) for WooComerce. (compatible with Indonesia banks/e-wallets only)

60 active installs v1.2.4 PHP 7.0+ WP 4.7+ Updated Sep 22, 2025
payment-gatewayqriswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pakasir for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Pakasir for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of "pakasir-for-woocommerce" v1.2.4 reveals a generally strong security posture. The plugin exhibits excellent practices by having no unauthenticated AJAX handlers or REST API routes, and all detected SQL queries utilize prepared statements, with all output being properly escaped. The absence of file operations and external HTTP requests further limits potential attack vectors. However, the lack of nonce checks and capability checks across all entry points, despite a small attack surface, presents a notable concern. This means that while the entry points are secured against direct unauthenticated access, authenticated users could potentially trigger functionality without explicit verification of their intent or permissions for specific actions, assuming the single REST API route is the only executable path. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of its security over time. This suggests the developers have a good understanding of secure coding practices. The primary weakness lies in the reliance on WordPress's inherent authentication without explicit re-verification at the plugin level for its limited entry points. Overall, the plugin is well-coded with minimal identified risks, but the absence of specific WordPress security checks could be exploited if the single REST API route has sensitive functionality.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

Pakasir for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pakasir for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Pakasir for WooCommerce Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/pakasir/v1/webhookincludes\class-wc-gateway-pakasir.php:169
WordPress Hooks 4
filterwoocommerce_payment_gatewaysincludes\class-wc-gateway-pakasir.php:107
actionrest_api_initincludes\class-wc-gateway-pakasir.php:168
actionplugins_loadedpakasir.php:26
actionwoocommerce_blocks_payment_method_type_registrationpakasir.php:39
Maintenance & Trust

Pakasir for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 22, 2025
PHP min version7.0
Downloads374

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Pakasir for WooCommerce Developer Profile

hdrxs312

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pakasir for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pakasir-for-woocommerce/includes/class-wc-gateway-pakasir.php/wp-content/plugins/pakasir-for-woocommerce/includes/class-wc-gateway-blocks-support.php/wp-content/plugins/pakasir-for-woocommerce/pakasir.php
Version Parameters
pakasir-for-woocommerce/pakasir.php?ver=pakasir-for-woocommerce/includes/class-wc-gateway-pakasir.php?ver=pakasir-for-woocommerce/includes/class-wc-gateway-blocks-support.php?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/pakasir/v1/webhook
FAQ

Frequently Asked Questions about Pakasir for WooCommerce