Payment Gateway CashBaba for WC Security & Risk Analysis

wordpress.org/plugins/payment-gateway-cashbaba-for-wc

You can easily pay via Cashbaba wallet.

0 active installs v1.0.0 PHP 7.1+ WP 5.3+ Updated Jul 12, 2021
cashbabacashbaba-walletmobile-walletpayment-gatewaywallet
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway CashBaba for WC Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway CashBaba for WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin 'payment-gateway-cashbaba-for-wc' v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of identified vulnerabilities in its history, coupled with the lack of dangerous functions, unsanitized taint flows, and a completely protected attack surface, are all positive indicators. The plugin also demonstrates good practices by ensuring all identified output is properly escaped.

However, there are areas that warrant attention. The presence of SQL queries that do not utilize prepared statements is a notable concern, as this can open the door to SQL injection vulnerabilities, even if none have been reported historically. Furthermore, the complete absence of nonce checks and capability checks across all entry points, although the current entry points are zero, suggests a potential for insecure code if new entry points are introduced without proper security considerations. The plugin also makes external HTTP requests, which, without further analysis of their purpose and implementation, could potentially introduce risks.

In conclusion, while the plugin is currently presenting a clean security profile with good output handling and no reported vulnerabilities, the unmitigated SQL queries and the complete lack of nonces and capability checks indicate potential weaknesses. If the plugin were to expand its attack surface or if the SQL queries handled user-supplied data, these areas would become significant risks. The current score reflects the good practices observed while acknowledging these potential underlying risks.

Key Concerns

  • SQL queries not using prepared statements
  • No nonce checks on any entry points
  • No capability checks on any entry points
  • External HTTP requests without clear context
Vulnerabilities
None known

Payment Gateway CashBaba for WC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Payment Gateway CashBaba for WC Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
0
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

100% escaped18 total outputs
Attack Surface

Payment Gateway CashBaba for WC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwoocommerce_receipt_cashbabaincludes\class-cashbaba-woocommerce-gateway.php:53
actionadmin_noticesincludes\class-cashbaba-woocommerce-gateway.php:143
actionplugins_loadedincludes\class-cashbaba-woocommerce.php:89
filterwoocommerce_payment_gatewaysincludes\class-cashbaba-woocommerce.php:90
actionplugins_loadedincludes\class-cashbaba-woocommerce.php:175
actionadmin_enqueue_scriptsincludes\class-cashbaba-woocommerce.php:190
actionadmin_enqueue_scriptsincludes\class-cashbaba-woocommerce.php:191
actionwp_enqueue_scriptsincludes\class-cashbaba-woocommerce.php:206
actionwp_enqueue_scriptsincludes\class-cashbaba-woocommerce.php:207
Maintenance & Trust

Payment Gateway CashBaba for WC Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJul 12, 2021
PHP min version7.1
Downloads909

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Payment Gateway CashBaba for WC Developer Profile

tapos007

2 plugins · 0 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway CashBaba for WC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-cashbaba-for-wc/admin/css/cashbaba-woocommerce-admin.css/wp-content/plugins/payment-gateway-cashbaba-for-wc/admin/js/cashbaba-woocommerce-admin.js
Script Paths
/wp-content/plugins/payment-gateway-cashbaba-for-wc/admin/js/cashbaba-woocommerce-admin.js
Version Parameters
cashbaba-woocommerce-admin.css?ver=cashbaba-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
Cashbaba_Woocommerce_Loader
FAQ

Frequently Asked Questions about Payment Gateway CashBaba for WC