PayPlus ipg Security & Risk Analysis

wordpress.org/plugins/payplus-ipg

PayPlus Payment Gateway Plugin for WooCommerce

0 active installs v1.0.0 PHP 7.0+ WP 6.2+ Updated Jun 10, 2025
mastersaved-cardsvisa
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PayPlus ipg Safe to Use in 2026?

Generally Safe

Score 100/100

PayPlus ipg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 'payplus-ipg' plugin v1.0.0 exhibits a mixed security posture, with some positive attributes but also significant vulnerabilities. On the positive side, the plugin avoids the use of dangerous functions, all SQL queries are properly prepared, and there are no recorded vulnerabilities or known CVEs. This suggests a developer who is mindful of common database and external threats. However, the static analysis reveals critical weaknesses regarding its attack surface. With two AJAX handlers, both lacking authentication checks, a significant portion of the plugin's functionality is exposed to unauthenticated users. This absence of authorization on entry points presents a substantial risk of unauthorized access and potential manipulation of plugin features.

The taint analysis also shows no identified flows, which is a positive indicator for preventing certain types of injection attacks. However, the lack of nonces and capability checks on the AJAX handlers, coupled with only 50% of output being properly escaped, means that even if no immediate taint flows are detected, there's still a risk of cross-site scripting (XSS) or other client-side attacks through the unprotected AJAX endpoints and insufficiently escaped output. The plugin's history of no vulnerabilities could indicate either a well-written codebase or simply a lack of exposure and testing, which is a double-edged sword. Overall, while the plugin demonstrates good practices in database interaction and avoids historical vulnerability patterns, the unprotected AJAX handlers represent a critical security concern that needs immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without capability checks
  • Unescaped output
  • AJAX handlers without nonce checks
Vulnerabilities
None known

PayPlus ipg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PayPlus ipg Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

PayPlus ipg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface
2 unprotected

PayPlus ipg Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_payplus_client_notepayplus-ipg.php:117
noprivwp_ajax_payplus_client_notepayplus-ipg.php:118
WordPress Hooks 13
actionwoocommerce_gateway_iconclasses\PayPlus_IPG_Gateway.php:41
actionwoocommerce_update_options_payment_gatewaysclasses\PayPlus_IPG_Gateway.php:46
actionadmin_noticespayplus-ipg.php:28
actionplugins_loadedpayplus-ipg.php:36
filterwoocommerce_payment_gatewayspayplus-ipg.php:40
actionbefore_woocommerce_initpayplus-ipg.php:65
actionwoocommerce_blocks_payment_method_type_registrationpayplus-ipg.php:77
actionwoocommerce_blocks_loadedpayplus-ipg.php:89
filterplugin_action_linkspayplus-ipg.php:103
actionwp_footerpayplus-ipg.php:127
actioninitpayplus-ipg.php:225
actionadmin_enqueue_scriptspayplus-ipg.php:227
actionwp_enqueue_scriptspayplus-ipg.php:228
Maintenance & Trust

PayPlus ipg Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version7.0
Downloads234

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PayPlus ipg Developer Profile

paypluslk

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayPlus ipg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payplus-ipg/assets/css/admin-style.css/wp-content/plugins/payplus-ipg/assets/js/crypto-js.min.js
Version Parameters
payplus-ipg/assets/css/admin-style.css?ver=payplus-ipg/assets/js/crypto-js.min.js?ver=

HTML / DOM Fingerprints

JS Globals
sessionStorage.getItem("pp_msg")
FAQ

Frequently Asked Questions about PayPlus ipg