PayzCore for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payzcore-for-woocommerce

Accept USDT and USDC stablecoin payments in your WooCommerce store via PayzCore blockchain transaction monitoring across multiple networks.

0 active installs v1.0.2 PHP 7.4+ WP 5.8+ Updated Mar 10, 2026
cryptocryptocurrencystablecoinusdcusdt
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayzCore for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

PayzCore for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'payzcore-for-woocommerce' plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, having a very low rate of unsanitized output, and no recorded vulnerabilities or critical taint flows. The absence of file operations and bundled libraries further contributes to a potentially more secure codebase. However, there are notable areas of concern. The presence of one unprotected REST API route represents a significant attack vector, as it lacks permission callbacks, meaning any user could potentially interact with it. Additionally, while the plugin has a limited attack surface overall, the fact that one of its entry points is unprotected warrants attention. The limited number of nonces and capability checks, especially in conjunction with the unprotected REST API route, suggests a potential weakness in enforcing proper authorization and security checks for certain functionalities. The plugin's history of no recorded vulnerabilities is encouraging but does not negate the risks identified in the current static analysis.

Key Concerns

  • Unprotected REST API route
  • 1 unprotected entry point
  • 0 capability checks
Vulnerabilities
None known

PayzCore for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PayzCore for WooCommerce Release Timeline

v1.0.2Current
Code Analysis
Analyzed Mar 17, 2026

PayzCore for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
143 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

95% escaped150 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<class-wc-gateway-payzcore> (includes\class-wc-gateway-payzcore.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

PayzCore for WooCommerce Attack Surface

Entry Points5
Unprotected1

AJAX Handlers 4

authwp_ajax_payzcore_check_statusincludes\class-wc-gateway-payzcore.php:99
noprivwp_ajax_payzcore_check_statusincludes\class-wc-gateway-payzcore.php:100
authwp_ajax_payzcore_confirm_txidincludes\class-wc-gateway-payzcore.php:101
noprivwp_ajax_payzcore_confirm_txidincludes\class-wc-gateway-payzcore.php:102

REST API Routes 1

POST/wp-json/payzcore/v1/webhookincludes\class-payzcore-webhook.php:36
WordPress Hooks 8
actionrest_api_initincludes\class-payzcore-webhook.php:27
actionadmin_enqueue_scriptsincludes\class-wc-gateway-payzcore.php:96
actionwoocommerce_email_before_order_tableincludes\class-wc-gateway-payzcore.php:97
actionwp_enqueue_scriptsincludes\class-wc-gateway-payzcore.php:98
actionadmin_noticespayzcore-woocommerce.php:77
filterwoocommerce_payment_gatewayspayzcore-woocommerce.php:85
actionplugins_loadedpayzcore-woocommerce.php:90
actionbefore_woocommerce_initpayzcore-woocommerce.php:117
Maintenance & Trust

PayzCore for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMar 10, 2026
PHP min version7.4
Downloads308

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PayzCore for WooCommerce Developer Profile

PayzCore

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayzCore for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payzcore-for-woocommerce/assets/images/usdt-icon.svg
Script Paths
/wp-content/plugins/payzcore-for-woocommerce/assets/js/payzcore-checkout.js/wp-content/plugins/payzcore-for-woocommerce/assets/js/payzcore-admin.js
Version Parameters
payzcore-for-woocommerce/assets/js/payzcore-checkout.js?ver=payzcore-for-woocommerce/assets/js/payzcore-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
payzcore-payment-detailspayzcore-qr-codepayzcore-countdownpayzcore-payment-address
HTML Comments
<!-- PayzCore Payment Details --><!-- PayzCore QR Code --><!-- PayzCore Countdown Timer -->
Data Attributes
data-payzcore-order-iddata-payzcore-payment-addressdata-payzcore-payment-amountdata-payzcore-networkdata-payzcore-token
JS Globals
PayzCoreCheckoutpayzcore_ajax_object
REST Endpoints
/wp-json/payzcore/v1/status//wp-json/payzcore/v1/confirm_txid/
FAQ

Frequently Asked Questions about PayzCore for WooCommerce