
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Security & Risk Analysis
wordpress.org/plugins/qh-testpayTích hợp thanh toán quét mã QR Code với MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Is Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Safe to Use in 2026?
Generally Safe
Score 85/100Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "qh-testpay" v1.0.2 plugin exhibits a concerning security posture due to a large number of unprotected entry points. While the plugin demonstrates good practices in handling SQL queries, its static analysis reveals a significant weakness: all six AJAX handlers and one REST API route lack authentication and permission checks. This opens a wide attack surface, making these endpoints vulnerable to unauthorized access and potential manipulation. Although no critical or high-severity taint flows were identified, the two flows with unsanitized paths warrant attention, as they could potentially lead to vulnerabilities if not properly handled. The absence of known CVEs and a clean vulnerability history is a positive indicator, suggesting the plugin has not historically been a target or source of serious security issues. However, the lack of documented security issues could also imply limited security scrutiny. Overall, the plugin has strengths in its database interaction but suffers from a critical deficiency in securing its communication endpoints, which significantly elevates its risk profile.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Flows with unsanitized paths
- Low output escaping rate
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Security Vulnerabilities
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 17
Maintenance & Trust
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Maintenance & Trust
Maintenance Signals
Community Trust
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Alternatives
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam
bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang
Tích hợp thanh toán quét mã QR Code MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng
casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang
Kết nối các ngân hàng Việt Nam vào Woocommerce, tự động xác nhận đơn hàng đã thanh toán. Hỗ trợ hơn 10 ngân hàng : VietinBank, OCB, Vietcombank, Techc …
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV
thanh-toan-chuyen-khoan
Tích hợp thanh toán quét mã QR Code với MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank Developer Profile
5 plugins · 140 total installs
How We Detect Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qh-testpay/assets/css/style.css/wp-content/plugins/qh-testpay/assets/js/easy.qrcode.js/wp-content/plugins/qh-testpay/assets/js/js.js/wp-content/plugins/qh-testpay/assets/js/easy.qrcode.js/wp-content/plugins/qh-testpay/assets/js/js.jsqh-testpay/assets/css/style.css?ver=qh-testpay/assets/js/easy.qrcode.js?ver=qh-testpay/assets/js/js.js?ver=HTML / DOM Fingerprints
QHTP_DIRQHTP_URLQHTP_TEST/wp-json/qh-testpay/