Payment Gateway for EasyPay Security & Risk Analysis

wordpress.org/plugins/payment-gateway-for-easywallet

Easy Wallet payment gateway for WooCommerce. Accept online payments in Armenian Dram (AMD) for your store.

0 active installs v2.0.0 PHP 8.0+ WP 5.0+ Updated Feb 6, 2026
easy-walleteasypay
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for EasyPay Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway for EasyPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "payment-gateway-for-easywallet" plugin version 2.0.0 presents a generally good security posture, with a strong emphasis on prepared statements for SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further contribute to a positive outlook. However, there are specific areas that warrant attention.

The static analysis reveals two flows with unsanitized paths during taint analysis. While these are not classified as critical or high severity, unsanitized paths can be a precursor to vulnerabilities if not properly handled. Additionally, the plugin performs file operations and external HTTP requests, which, while not inherently insecure, introduce potential attack vectors if not rigorously secured against path traversal or injection attacks.

Despite these minor concerns, the plugin demonstrates good security practices such as a decent number of nonce and capability checks, and no dangerous functions identified. The lack of significant vulnerability history is a strong positive indicator. The plugin's security is largely sound, but the identified unsanitized paths require thorough review and remediation to ensure robust protection.

Key Concerns

  • Flows with unsanitized paths found
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Payment Gateway for EasyPay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Payment Gateway for EasyPay Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
11 prepared
Unescaped Output
17
67 escaped
Nonce Checks
3
Capability Checks
2
File Operations
1
External Requests
6
Bundled Libraries
0

SQL Query Safety

92% prepared12 total queries

Output Escaping

80% escaped84 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
hkdigital_easywallet_intercept_callback (includes\main.php:10)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payment Gateway for EasyPay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
filtercron_schedulesconsole\command.php:22
actioninitconsole\command.php:32
actionadmin_initincludes\activate.php:3
actioninitincludes\main.php:9
actioninitincludes\main.php:34
actionwoocommerce_api_easy_wallet_responseincludes\main.php:106
actionwoocommerce_api_easypay_resultincludes\main.php:107
filterwoocommerce_available_payment_gatewaysincludes\main.php:111
actionadmin_enqueue_scriptsincludes\main.php:114
actionhkdigital_cronCheckOrderEasyWalletincludes\main.php:121
actionhkdigital_cron_cleanup_easywallet_logsincludes\main.php:124
filterwoocommerce_payment_gatewayswc-hkdigital-easy-wallet-gateway.php:47
actionwoocommerce_blocks_loadedwc-hkdigital-easy-wallet-gateway.php:72
actionwoocommerce_blocks_payment_method_type_registrationwc-hkdigital-easy-wallet-gateway.php:78
actionbefore_woocommerce_initwc-hkdigital-easy-wallet-gateway.php:101
actionadmin_menuwc-hkdigital-easy-wallet-gateway.php:104

Scheduled Events 2

hkdigital_cronCheckOrderEasyWallet
hkdigital_cron_cleanup_easywallet_logs
Maintenance & Trust

Payment Gateway for EasyPay Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 6, 2026
PHP min version8.0
Downloads116

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Payment Gateway for EasyPay Developer Profile

HK Digital Agency LLC

11 plugins · 660 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
456 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for EasyPay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-for-easy-wallet/assets/js/easy-wallet-gateway.js/wp-content/plugins/payment-gateway-for-easy-wallet/assets/css/easy-wallet-gateway.css
Script Paths
easy-wallet-gateway.js
Version Parameters
payment-gateway-for-easy-wallet/assets/js/easy-wallet-gateway.js?ver=payment-gateway-for-easy-wallet/assets/css/easy-wallet-gateway.css?ver=

HTML / DOM Fingerprints

CSS Classes
hkd-easywallet-logs-list-tablehkd-easywallet-log-entry
HTML Comments
<!-- [FIX #18] Verify nonce for CSV export -->
Data Attributes
data-easywallet-gateway-settings
JS Globals
easyWalletGateway
REST Endpoints
/wp-json/easywallet/v1/payment-request
FAQ

Frequently Asked Questions about Payment Gateway for EasyPay