Paypercut Payments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/paypercut-payments-for-woocommerce

Paypercut Payments enables WooCommerce merchants to accept online payments using Paypercut's checkout experience.

20 active installs v0.1.4 PHP 7.4+ WP 6.6+ Updated Mar 14, 2026
checkoutecommercepayment-gatewaypaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paypercut Payments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Paypercut Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 20d ago
Risk Assessment

The "paypercut-payments-for-woocommerce" plugin, version 0.1.4, presents a concerning security posture due to a significant number of unprotected entry points. While the code shows good practices in areas like SQL query preparation and output escaping, the presence of 6 AJAX handlers without any authentication checks creates a wide attack surface. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if the handler logic is not robust.

The static analysis did not reveal critical or high severity taint flows, nor are there any known historical vulnerabilities (CVEs). This suggests that while the plugin may not have been targeted or exploited in the past, the current architecture introduces inherent risks. The lack of direct vulnerabilities in the historical data is positive, but it cannot compensate for the immediate risks posed by the unprotected AJAX endpoints.

In conclusion, the plugin demonstrates strengths in its secure handling of SQL and output data. However, the critical weakness lies in the unprotected AJAX handlers. This oversight significantly increases the risk of potential exploitation, and it's crucial for this to be addressed. The absence of historical vulnerabilities is a good sign, but it does not mitigate the current structural security gaps.

Key Concerns

  • Unprotected AJAX handlers
  • High number of unprotected entry points
  • Bundled Guzzle library potentially outdated
Vulnerabilities
None known

Paypercut Payments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Paypercut Payments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
144 escaped
Nonce Checks
7
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

97% escaped148 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle (src\Http\Ajax\SetupWizard.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Paypercut Payments for WooCommerce Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_paypercut_create_checkout_sessionsrc\Plugin.php:53
noprivwp_ajax_paypercut_create_checkout_sessionsrc\Plugin.php:54
authwp_ajax_paypercut_setup_wizardsrc\Plugin.php:57
authwp_ajax_paypercut_test_connectionsrc\Plugin.php:60
authwp_ajax_paypercut_delete_webhooksrc\Plugin.php:63
authwp_ajax_paypercut_create_webhooksrc\Plugin.php:66
WordPress Hooks 14
actionbefore_woocommerce_initpaypercut-payments-for-woocommerce.php:61
actionwoocommerce_blocks_loadedpaypercut-payments-for-woocommerce.php:80
actionwoocommerce_blocks_payment_method_type_registrationpaypercut-payments-for-woocommerce.php:85
actionplugins_loadedpaypercut-payments-for-woocommerce.php:103
filterwoocommerce_payment_methods_list_itemsrc\Gateway\PaypercutGateway.php:112
filterwoocommerce_payment_token_classsrc\Plugin.php:46
filterwoocommerce_payment_gatewayssrc\Plugin.php:47
actionadmin_enqueue_scriptssrc\Plugin.php:48
actionwp_enqueue_scriptssrc\Plugin.php:49
actionrest_api_initsrc\Plugin.php:68
actionwoocommerce_before_thankyousrc\Plugin.php:77
actionwoocommerce_before_thankyousrc\Plugin.php:80
actionwoocommerce_rest_checkout_process_payment_with_contextsrc\Plugin.php:82
filterwoocommerce_my_account_my_orders_actionssrc\Plugin.php:84
Maintenance & Trust

Paypercut Payments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.4
Downloads249

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Paypercut Payments for WooCommerce Developer Profile

Paypercut Dev

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paypercut Payments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paypercut-payments-for-woocommerce/admin/css/settings.css/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/test-connection.js/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/delete-webhook.js/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/create-webhook.js/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/setup-wizard.js
Script Paths
/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/test-connection.js/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/delete-webhook.js/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/create-webhook.js/wp-content/plugins/paypercut-payments-for-woocommerce/admin/js/setup-wizard.js
Version Parameters
paypercut-payments-for-woocommerce/admin/css/settings.css?ver=paypercut-payments-for-woocommerce/admin/js/test-connection.js?ver=paypercut-payments-for-woocommerce/admin/js/delete-webhook.js?ver=paypercut-payments-for-woocommerce/admin/js/create-webhook.js?ver=paypercut-payments-for-woocommerce/admin/js/setup-wizard.js?ver=

HTML / DOM Fingerprints

JS Globals
paypercutTestConnectionpaypercutAdminpaypercutSetupWizard
FAQ

Frequently Asked Questions about Paypercut Payments for WooCommerce