ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Security & Risk Analysis

wordpress.org/plugins/scanforpay-alipay-alipayhk-for-woocommerce

ScanForPay幫助香港商戶使用支付寶、AlipayHK、WechatPay在WooCommerce商城中收款. ScanForPay helps merchants in HongKong to accept Alipay、AlipayHK and WechatPay on their Wo …

90 active installs v1.1.9 PHP 5.4.16+ WP 4.9.10+ Updated Jan 9, 2026
alipayalipayhkcrossborderpaymentscanforpay
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of 'scanforpay-alipay-alipayhk-for-woocommerce' v1.1.9 reveals a generally strong security posture in terms of common web application vulnerabilities. The plugin has no recorded CVEs, no detected dangerous functions, and all SQL queries utilize prepared statements. Furthermore, all output appears to be properly escaped, and there are no external HTTP requests, mitigating risks associated with data injection or remote code execution through these vectors. The absence of taint analysis findings further suggests that data flowing through the plugin is handled with care regarding potential malicious manipulation.

However, the analysis does highlight areas for potential concern. The plugin performs a significant number of file operations (17) without any mention of checks or sanitization for these operations, which could present a risk if not handled securely. Additionally, the complete absence of nonce checks and capability checks, combined with zero detected entry points that are unprotected, is an unusual finding. While it might indicate that all potential entry points are inherently protected by WordPress core or that there are no exposed entry points, it's a signal that warrants further manual inspection. A large number of file operations without clear protective measures alongside a complete lack of explicit security checks (nonces, capabilities) on entry points, even if no unprotected ones are detected, represents a potential blind spot.

Overall, the plugin shows strengths in its handling of SQL and output, and its vulnerability history is clean. However, the extensive file operations without explicit security controls and the absence of common WordPress security mechanisms like nonces and capability checks on its (apparently limited) attack surface suggest that while the direct attack vectors may be minimal in this version, a deeper review of file operation security and the reasoning behind the lack of explicit checks would be prudent to ensure a robust security posture.

Key Concerns

  • Significant file operations without apparent checks
  • No nonce checks on potential entry points
  • No capability checks on potential entry points
Vulnerabilities
None known

ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
17
External Requests
0
Bundled Libraries
0
Attack Surface

ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-alipayhk-gateway.php:66
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-alipayhk-gateway.php:67
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-alipayplus-gateway.php:66
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-alipayplus-gateway.php:67
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-apple-gateway.php:66
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-apple-gateway.php:67
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-card-gateway.php:66
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-card-gateway.php:67
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-gateway.php:64
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-gateway.php:65
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-google-gateway.php:66
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-google-gateway.php:67
actionwoocommerce_api_payment_notifyincludes\wc-scanforpay-wechat-gateway.php:66
actionwoocommerce_api_payment_callbackincludes\wc-scanforpay-wechat-gateway.php:67
actionplugins_loadedscanforpay-alipay-for-woocommerce.php:12
filterwoocommerce_payment_gatewaysscanforpay-alipay-for-woocommerce.php:43
Maintenance & Trust

ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 9, 2026
PHP min version5.4.16
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce Developer Profile

scanforpay

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scanforpay-alipay-alipayhk-for-woocommerce/assets/js/scanforpay-alipay.js/wp-content/plugins/scanforpay-alipay-alipayhk-for-woocommerce/assets/css/scanforpay.css
Version Parameters
scanforpay-alipay-alipayhk-for-woocommerce/assets/css/scanforpay.css?ver=scanforpay-alipay-alipayhk-for-woocommerce/assets/js/scanforpay-alipay.js?ver=

HTML / DOM Fingerprints

CSS Classes
scanforpay-gateway-settingsscanforpay-notice
Data Attributes
data-scanforpay-gateway
JS Globals
scanforpay_gateway_params
FAQ

Frequently Asked Questions about ScanForPay – Alipay & AlipayHK & WechatPay Payment Solutions for WooCommerce