
PayPlus ipg Security & Risk Analysis
wordpress.org/plugins/payplus-ipgPayPlus Payment Gateway Plugin for WooCommerce
Is PayPlus ipg Safe to Use in 2026?
Generally Safe
Score 100/100PayPlus ipg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'payplus-ipg' plugin v1.0.0 exhibits a mixed security posture, with some positive attributes but also significant vulnerabilities. On the positive side, the plugin avoids the use of dangerous functions, all SQL queries are properly prepared, and there are no recorded vulnerabilities or known CVEs. This suggests a developer who is mindful of common database and external threats. However, the static analysis reveals critical weaknesses regarding its attack surface. With two AJAX handlers, both lacking authentication checks, a significant portion of the plugin's functionality is exposed to unauthenticated users. This absence of authorization on entry points presents a substantial risk of unauthorized access and potential manipulation of plugin features.
The taint analysis also shows no identified flows, which is a positive indicator for preventing certain types of injection attacks. However, the lack of nonces and capability checks on the AJAX handlers, coupled with only 50% of output being properly escaped, means that even if no immediate taint flows are detected, there's still a risk of cross-site scripting (XSS) or other client-side attacks through the unprotected AJAX endpoints and insufficiently escaped output. The plugin's history of no vulnerabilities could indicate either a well-written codebase or simply a lack of exposure and testing, which is a double-edged sword. Overall, while the plugin demonstrates good practices in database interaction and avoids historical vulnerability patterns, the unprotected AJAX handlers represent a critical security concern that needs immediate attention.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without capability checks
- Unescaped output
- AJAX handlers without nonce checks
PayPlus ipg Security Vulnerabilities
PayPlus ipg Release Timeline
PayPlus ipg Code Analysis
Output Escaping
PayPlus ipg Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
PayPlus ipg Maintenance & Trust
Maintenance Signals
Community Trust
PayPlus ipg Alternatives
PixelPay ipg
pixelpay-ipg
PixelPay Payment Gateway Plugin for WooCommerce
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Frisbii Pay
reepay-checkout-gateway
Accept Visa, MasterCard, Dankort, MobilePay, American Express, Diners Club and more directly on your store with the Frisbii Pay Gateway.
IntaSend Payment
intasend-payment
Securely collect M-Pesa and card payments (Visa and Mastercard) (WooCommerce Plugin).
Pagadito Payment Gateway for WooCommerce
woo-pagadito-payment-gateway
Pagadito allows you to pay online in a safe, easy and reliable way.
PayPlus ipg Developer Profile
1 plugin · 0 total installs
How We Detect PayPlus ipg
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payplus-ipg/assets/css/admin-style.css/wp-content/plugins/payplus-ipg/assets/js/crypto-js.min.jspayplus-ipg/assets/css/admin-style.css?ver=payplus-ipg/assets/js/crypto-js.min.js?ver=HTML / DOM Fingerprints
sessionStorage.getItem("pp_msg")