Payyed Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payyed-gateway-for-woocommerce

Accept payments from MPESA, Credit Cards, Debit Cards via Payyed.org, we host all payment gateways making it flexible to shift between any at will.

10 active installs v1.3.7 PHP 7.4+ WP 5.5+ Updated Jan 27, 2025
mpesaopskill-pluginspayment-gatewaypaystackwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payyed Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Payyed Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'payyed-gateway-for-woocommerce' plugin version 1.3.7 exhibits a strong security posture with several positive indicators. The complete absence of known CVEs and a clean vulnerability history suggest a history of secure development and maintenance. Furthermore, the static analysis reveals no dangerous functions, no direct SQL queries (all are prepared statements), and all identified outputs are properly escaped. The absence of critical or high severity taint flows is also a very positive sign, indicating that data is not being mishandled in a way that would typically lead to severe vulnerabilities like remote code execution or SQL injection.

However, there are areas that warrant attention. The plugin's static analysis shows zero nonce checks and zero capability checks across all identified entry points, which are all currently reported as protected. While the current configuration might not expose any vulnerabilities, this lack of fundamental security checks presents a significant concern. If the plugin were to evolve and introduce new entry points, or if the definition of 'protected' entry points changes, these missing checks could expose the plugin to serious privilege escalation or unauthorized action vulnerabilities. The presence of file operations and external HTTP requests, while not inherently bad, are also points that require careful scrutiny in a real-world scenario to ensure they are implemented securely and do not introduce unforeseen risks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Payyed Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Payyed Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Payyed Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedpayyed-payment-for-woocommerce.php:26
filterwoocommerce_checkout_fieldspayyed-payment-for-woocommerce.php:29
actionphpmailer_initpayyed-payment-for-woocommerce.php:234
filterwoocommerce_payment_gatewayspayyed-payment-for-woocommerce.php:576
Maintenance & Trust

Payyed Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 27, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Payyed Gateway for WooCommerce Developer Profile

qqqjus

2 plugins · 10 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payyed Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payyed-gateway-for-woocommerce/assets/icon.png

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Payyed Gateway for WooCommerce