PayPlus Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payplus-gateway

Accept Alipay, WeChat Pay, Credit Cards in one plugin for WooCommerce.

0 active installs v1.0.2 PHP 7.0+ WP 4.7+ Updated Mar 1, 2024
alipaycredit-cardpaymentpayment-gatewaywechat-pay
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayPlus Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

PayPlus Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The payplus-gateway plugin v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries that are exclusively prepared, and a high percentage of properly escaped output are positive indicators. Furthermore, the plugin has no recorded vulnerability history, suggesting a consistent track record of security. However, there are notable concerns stemming from the lack of nonces and capability checks for its entry points, which are currently zero. This could indicate an oversight in the development process, where security checks might have been overlooked or considered unnecessary due to the perceived limited attack surface. The presence of file operations and external HTTP requests without explicit mention of sanitization or authentication for these operations also warrants caution.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • One file operation without auth/sanitization context
  • One external HTTP request without auth/sanitization context
  • Minor unescaped output (6% of total)
Vulnerabilities
None known

PayPlus Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PayPlus Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

94% escaped17 total outputs
Attack Surface

PayPlus Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedindex.php:12
actionwoocommerce_update_options_payment_gatewaysindex.php:49
actionwoocommerce_receipt_ppgenericindex.php:51
actionwoocommerce_api_wc_pp_genericindex.php:54
actionwoocommerce_api_wc_ppgeneric_success_pageindex.php:57
actionthe_contentindex.php:337
filterwoocommerce_payment_gatewaysindex.php:423
Maintenance & Trust

PayPlus Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedMar 1, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PayPlus Gateway for WooCommerce Developer Profile

seanpayplus

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayPlus Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payplus-gateway/assets/icon-256x256.jpg

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wc_pp_generic/wp-json/wc_ppgeneric_success_page
FAQ

Frequently Asked Questions about PayPlus Gateway for WooCommerce