payabl. Payments Gateway Security & Risk Analysis

wordpress.org/plugins/powercash21-payments-gateway

Accept payments on your store using payabl. Payment Gateway on Woocommerce platform for Wordpress Sites.

30 active installs v3.1.4.1 PHP 8.0+ WP 6.5+ Updated Mar 11, 2026
applepaycreditcardepsgooglepaypaypal
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is payabl. Payments Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

payabl. Payments Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

The powercash21-payments-gateway plugin exhibits a concerning security posture due to a significant number of unprotected entry points into its codebase. While the plugin demonstrates good practices in areas like SQL query handling and output escaping, the presence of two REST API routes without permission callbacks represents a direct avenue for potential unauthorized access or manipulation. The taint analysis, although not revealing critical or high severity flaws, did highlight flows with unsanitized paths, which can be a precursor to vulnerabilities if not carefully managed. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a diligent development approach regarding known security issues. However, this does not negate the immediate risks posed by the unauthenticated entry points identified in the static analysis. The plugin needs to address the exposed REST API endpoints to mitigate the risk of unauthorized actions.

Key Concerns

  • REST API routes without permission callbacks
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

payabl. Payments Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

payabl. Payments Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
63 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
7
Bundled Libraries
0

Output Escaping

89% escaped71 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
process_payment (includes\payment-methods\class-wc-gateway-amex.php:97)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

payabl. Payments Gateway Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

GET/wp-json/payabl-checkout/api/v1/returnclass-wc-gateway-payabl.php:884
GET/wp-json/payabl-checkout/api/v1/return(?P<extra>.*)class-wc-gateway-payabl.php:891
WordPress Hooks 12
actionplugins_loadedclass-wc-gateway-payabl.php:36
actionwp_enqueue_scriptsclass-wc-gateway-payabl.php:38
actionwoocommerce_order_status_cancelledclass-wc-gateway-payabl.php:39
actionrest_api_initclass-wc-gateway-payabl.php:40
actionwoocommerce_before_thankyouclass-wc-gateway-payabl.php:41
actionadmin_noticesclass-wc-gateway-payabl.php:59
filterwoocommerce_payment_gatewaysclass-wc-gateway-payabl.php:144
filterwoocommerce_gateway_iconclass-wc-gateway-payabl.php:146
actionbefore_woocommerce_initclass-wc-gateway-payabl.php:178
filterwoocommerce_gateway_descriptionclass-wc-gateway-payabl.php:294
actionwoocommerce_checkout_processclass-wc-gateway-payabl.php:372
actionwoocommerce_api_wc_gateway_powercash21class-wc-gateway-payabl.php:414
Maintenance & Trust

payabl. Payments Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 11, 2026
PHP min version8.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

payabl. Payments Gateway Developer Profile

Fazley

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect payabl. Payments Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/powercash21-payments-gateway/assets/payabl_amex.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_applepay.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_hosted.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_eps.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_googlepay.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_ideal.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_paypal.png/wp-content/plugins/powercash21-payments-gateway/assets/payabl_p24.png+4 more

HTML / DOM Fingerprints

CSS Classes
payabl-payment-form
Data Attributes
data-payabl-gateway-id
JS Globals
payablPAYABL_WC_PLUGIN_URL
REST Endpoints
/wp-json/payabl/v1/apple-pay-validation
FAQ

Frequently Asked Questions about payabl. Payments Gateway