Pleenk Payment Security & Risk Analysis

wordpress.org/plugins/pleenk-payment

Allow woocommerce pay with Pleenk

0 active installs v1.0.2 PHP 7.1+ WP 4.7+ Updated Aug 21, 2025
bitcoin-paymentethereum-paymentpayment-gatewaypleenk-paymentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pleenk Payment Safe to Use in 2026?

Generally Safe

Score 100/100

Pleenk Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The static analysis of the pleenk-payment plugin v1.0.2 reveals a generally strong security posture, with no critical vulnerabilities identified in code signals or taint analysis. The absence of dangerous functions, the use of prepared statements for all SQL queries, and a high percentage of properly escaped output are commendable practices. The plugin also demonstrates good security by avoiding external HTTP requests and handling file operations cautiously, based on the provided data.

However, there are significant concerns arising from the lack of authentication and authorization checks across all identified entry points. With zero AJAX handlers, REST API routes, shortcodes, or cron events requiring authentication or capability checks, the entire plugin's functionality is potentially exposed to unauthenticated users. This represents a substantial attack surface that, while currently showing no specific vulnerabilities in the static analysis, creates a high risk of potential exploits if any functionality is inadvertently exposed or if new entry points are introduced without proper security controls. The vulnerability history being empty is a positive sign, but it doesn't negate the inherent risk introduced by the lack of robust access controls.

In conclusion, while pleenk-payment v1.0.2 exhibits good internal coding practices regarding SQL and output sanitization, its security is severely undermined by the complete absence of authentication and authorization checks on its entry points. This makes it highly susceptible to unauthorized access and manipulation, a critical weakness that far outweighs its positive attributes. The plugin would benefit immensely from implementing robust access controls for all its functionalities.

Key Concerns

  • No capability checks across entry points
  • No nonce checks on AJAX handlers
  • High percentage of unescaped output (7%)
Vulnerabilities
None known

Pleenk Payment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pleenk Payment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
20
External Requests
2
Bundled Libraries
0

Output Escaping

93% escaped28 total outputs
Attack Surface

Pleenk Payment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionwoocommerce_api_wc_pleenk_returnapp\payment.php:103
actionwoocommerce_api_wc_pleenk_notifyapp\payment.php:104
actionwoocommerce_api_wc_pleenk_checkapp\payment.php:105
actionwp_enqueue_scriptsapp\payment.php:374
actionplugins_loadedindex.php:25
filterwoocommerce_payment_gatewaysindex.php:46
actionbefore_woocommerce_initindex.php:52
actionwoocommerce_blocks_loadedindex.php:61
actionwoocommerce_blocks_payment_method_type_registrationindex.php:69
actionwoocommerce_api_wc_pleenk_returntrunk\app\payment.php:103
actionwoocommerce_api_wc_pleenk_notifytrunk\app\payment.php:104
actionwoocommerce_api_wc_pleenk_checktrunk\app\payment.php:105
actionwp_enqueue_scriptstrunk\app\payment.php:374
actionplugins_loadedtrunk\index.php:25
filterwoocommerce_payment_gatewaystrunk\index.php:46
actionbefore_woocommerce_inittrunk\index.php:52
actionwoocommerce_blocks_loadedtrunk\index.php:61
actionwoocommerce_blocks_payment_method_type_registrationtrunk\index.php:69
Maintenance & Trust

Pleenk Payment Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 21, 2025
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pleenk Payment Developer Profile

Pleenk

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pleenk Payment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pleenk-payment/app/build/static/js/bundle.js/wp-content/plugins/pleenk-payment/app/build/static/css/main.css
Script Paths
/wp-content/plugins/pleenk-payment/app/build/static/js/bundle.js
Version Parameters
pleenk-payment/app/build/static/js/bundle.js?ver=pleenk-payment/app/build/static/css/main.css?ver=

HTML / DOM Fingerprints

CSS Classes
pleenk-payment-form
Data Attributes
data-pleenk-payment-form
JS Globals
window.Pleenkvar pleenk_payment_params
Shortcode Output
[pleenk_payment_form]
FAQ

Frequently Asked Questions about Pleenk Payment