
PayPlus Payment Gateway Security & Risk Analysis
wordpress.org/plugins/payplus-payment-gatewayAccept credit/debit card payments or other methods such as bit, Apple Pay, Google Pay in one page. Create digitally signed invoices & much more!
Is PayPlus Payment Gateway Safe to Use in 2026?
Generally Safe
Score 93/100PayPlus Payment Gateway has a strong security track record. Known vulnerabilities have been patched promptly.
The "payplus-payment-gateway" plugin version 8.1.5 exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of SQL prepared statements and nonce checks on AJAX handlers, there are significant areas of concern. The static analysis reveals "Flows with unsanitized paths" in the taint analysis, with one flagged as high severity. This suggests potential vulnerabilities where user input could be processed without adequate sanitization, leading to unexpected behavior or security risks. Furthermore, the plugin has a history of known vulnerabilities, including critical Cross-site Scripting (XSS) and SQL Injection issues. Although there are no currently unpatched CVEs, this pattern indicates a recurring tendency for severe vulnerabilities to be introduced into the plugin, requiring diligent attention from developers and users alike. The overall attack surface is sizable, though importantly, all identified entry points have authentication checks, which is a positive mitigating factor. However, the presence of high-severity taint flows and the historical vulnerability trends necessitate caution.
Key Concerns
- High severity taint flow found
- Multiple flows with unsanitized paths
- History of critical vulnerabilities
- History of medium vulnerabilities
- Less than ideal output escaping (83%)
PayPlus Payment Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
PayPlus Payment Gateway <= 7.0.7 - Authenticated (Subscriber+) SQL Injection
PayPlus Payment Gateway <= 6.6.8 - Reflected Cross-Site Scripting
PayPlus Payment Gateway <= 6.6.8 - Unauthenticated SQL Injection
PayPlus Payment Gateway Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PayPlus Payment Gateway Attack Surface
AJAX Handlers 35
Shortcodes 1
WordPress Hooks 104
Scheduled Events 3
Maintenance & Trust
PayPlus Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
PayPlus Payment Gateway Alternatives
Payment Plugins for PayPal WooCommerce
pymntpl-paypal-woocommerce
Developed exclusively between Payment Plugins and PayPal, PayPal for WooCommerce integrates with PayPal's newest API's.
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple to use, all-in-one platform, that anyone can set up in just a few minutes!
Subscriptions for WooCommerce
subscriptions-for-woocommerce
With WooCommerce Subscription, turn your physical or online store into a WooCommerce product subscription store and avail recurring revenue.
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Payment Gateway for PayPal on WooCommerce
woo-paypal-gateway
PayPal, Credit/Debit Cards, Google Pay, Apple Pay, Pay Later, Venmo, SEPA, iDEAL, Mercado Pago, Bancontact & more - by an official PayPal Partner
PayPlus Payment Gateway Developer Profile
4 plugins · 1K total installs
How We Detect PayPlus Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payplus-payment-gateway/assets/css/payplus.css/wp-content/plugins/payplus-payment-gateway/assets/js/payplus.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus-applepay.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus-hosted-fields.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus-thankyou.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus-applepay.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus-hosted-fields.js/wp-content/plugins/payplus-payment-gateway/assets/js/payplus-thankyou.jspayplus-payment-gateway/assets/css/payplus.css?ver=payplus-payment-gateway/assets/js/payplus.js?ver=payplus-payment-gateway/assets/js/payplus-applepay.js?ver=payplus-payment-gateway/assets/js/payplus-hosted-fields.js?ver=payplus-payment-gateway/assets/js/payplus-thankyou.js?ver=HTML / DOM Fingerprints
payplus-payment-gatewaydata-payplus-checkout-urldata-payplus-thankyou-urldata-payplus-order-iddata-payplus-currencydata-payplus-amountpayplus_payment_gatewaypayplus_varspayplus_data/wp-json/payplus/v1/order/status