
Scanandpay Payments via PayID for WooCommerce Security & Risk Analysis
wordpress.org/plugins/scanandpay-payments-via-payid-for-woocommerceAccept PayID payments in your WooCommerce store. Customers scan a QR code and pay instantly via their banking app.
Is Scanandpay Payments via PayID for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Scanandpay Payments via PayID for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scanandpay-payments-via-payid-for-woocommerce" plugin, version 1.1.8, demonstrates a generally good security posture with several strengths. The absence of dangerous functions, file operations, and SQL queries using prepared statements is highly positive. Furthermore, the plugin exhibits robust output escaping and has no recorded vulnerability history, suggesting a commitment to secure development.
However, there are areas for concern that slightly detract from its overall security. The presence of one REST API route without a permission callback represents a potential entry point for unauthorized access or manipulation if not properly secured by the underlying WordPress environment or other plugins. While the taint analysis shows no issues, the small number of flows analyzed might not be exhaustive. The limited number of capability checks (1) and nonce checks (3) compared to the number of entry points could also be a concern if these are not sufficiently comprehensive across all critical operations.
In conclusion, the plugin is built on a foundation of secure coding practices, indicated by the lack of critical vulnerabilities and good handling of SQL and output. The primary weakness lies in a single unprotected REST API route. Continued vigilance in expanding authorization checks and comprehensive taint analysis would further strengthen its security profile.
Key Concerns
- REST API route without permission callback
- Limited nonce checks relative to entry points
- Limited capability checks relative to entry points
Scanandpay Payments via PayID for WooCommerce Security Vulnerabilities
Scanandpay Payments via PayID for WooCommerce Code Analysis
Output Escaping
Scanandpay Payments via PayID for WooCommerce Attack Surface
AJAX Handlers 5
REST API Routes 1
Shortcodes 1
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
Scanandpay Payments via PayID for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Scanandpay Payments via PayID for WooCommerce Alternatives
Bangladeshi Payment Gateways – Make Payment Using QR Code
bangladeshi-payment-gateways
Bangladeshi Payment Gateways for WooCommerce.
HitPay Payment Gateway for WooCommerce
hitpay-payment-gateway
HitPay Payment Gateway Plugin allows HitPay merchants to accept PayNow QR, Cards, Apple Pay, Google Pay, WeChatPay, AliPay and GrabPay Payments.
Debitsuccess
debitsuccess
Accept all major credit cards directly on your WooCommerce site in a seamless and secure checkout environment with Debitsuccess Commerce.
Frinext Scan & Pay
frinextqr
Manual UPI Scan & Pay payment gateway for WooCommerce with QR code and payment proof upload.
SSV Smart Pay Payment Gateway
ssv-smart-pay-payment-gateway
Accept payments via Pay by Bank - SSV SmartPay Payment Gateway using QR code or bank transfer. Fast, secure, and easy to use for WooCommerce stores.
Scanandpay Payments via PayID for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Scanandpay Payments via PayID for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scanandpay-payments-via-payid-for-woocommerce/assets/css/admin.css/wp-content/plugins/scanandpay-payments-via-payid-for-woocommerce/assets/js/admin-connection-test.js/wp-content/plugins/scanandpay-payments-via-payid-for-woocommerce/assets/js/admin-connection-test.jsscanandpay-payments-via-payid-for-woocommerce/assets/css/admin.css?ver=scanandpay-payments-via-payid-for-woocommerce/assets/js/admin-connection-test.js?ver=HTML / DOM Fingerprints
scanpay-woo-admin-test-connect-buttondata-gateway-id="scanpay"ScanPayAdminTest/wp-json/scanpay-woo/v1/webhook/wp-json/scanpay-woo/v1/payment_status