
PayHere Payment Gateway – Beta Security & Risk Analysis
wordpress.org/plugins/payhere-payment-gateway-betaPayHere Payment Gateway Plugin for WooCommerce
Is PayHere Payment Gateway – Beta Safe to Use in 2026?
Generally Safe
Score 100/100PayHere Payment Gateway – Beta has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "payhere-payment-gateway-beta" v2.5.3 presents a mixed security posture. On the positive side, the static analysis indicates robust practices regarding SQL queries, as all are properly prepared, and a high percentage of output escaping is correctly implemented. The absence of file operations and the lack of recorded historical vulnerabilities are also positive indicators. However, significant concerns arise from the attack surface. The plugin exposes three AJAX handlers, all of which lack authentication checks. This is a critical oversight that could allow unauthenticated users to trigger potentially sensitive actions. Furthermore, the complete absence of nonce checks on these AJAX actions exacerbates this risk, making them vulnerable to Cross-Site Request Forgery (CSRF) attacks.
The taint analysis did not reveal any specific vulnerabilities, which is a positive sign. However, the lack of analysis flows suggests that either the analysis was incomplete or the plugin's code paths are not complex enough to trigger the taint analysis tool. The plugin's history of zero known CVEs is encouraging, suggesting a history of secure development or limited exposure. Despite the positive aspects of data handling and the clean vulnerability history, the unprotected AJAX endpoints represent a substantial security risk that needs immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- No nonce checks on AJAX handlers
- Large attack surface without authorization
PayHere Payment Gateway – Beta Security Vulnerabilities
PayHere Payment Gateway – Beta Code Analysis
SQL Query Safety
Output Escaping
PayHere Payment Gateway – Beta Attack Surface
AJAX Handlers 3
WordPress Hooks 30
Maintenance & Trust
PayHere Payment Gateway – Beta Maintenance & Trust
Maintenance Signals
Community Trust
PayHere Payment Gateway – Beta Alternatives
PayHere Payment Gateway
payhere-payment-gateway
PayHere Payment Gateway
Mintpay
mintpay
Mintpay, Sri Lanka's first buy now, pay later platform offers 0% interest and no hidden fees.
Pics Payment Gateway
pics-payment-gateway
Pics Payment Gateway Plugin for WooCommerce
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple to use, all-in-one platform, that anyone can set up in just a few minutes!
Paysera Payment Gateway for WooCommerce
woo-payment-gateway-paysera
Paysera payments + delivery
PayHere Payment Gateway – Beta Developer Profile
2 plugins · 2K total installs
How We Detect PayHere Payment Gateway – Beta
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payhere-payment-gateway-beta/admin/css/payhere-ipg-admin.css/wp-content/plugins/payhere-payment-gateway-beta/admin/css/payhere-customer-list-settings.csspayhere-payment-gateway-beta/admin/css/payhere-ipg-admin.css?ver=payhere-payment-gateway-beta/admin/css/payhere-customer-list-settings.css?ver=HTML / DOM Fingerprints
image-selection-wrapperadd-mediaremove-mediaset-defaultCurrently plugin version.The code that runs during plugin activation.The code that runs during plugin deactivation.Add function to remove old transaction logs.+12 moreimage-selection-wrapperadd-mediaremove-mediaset-default