seQura Security & Risk Analysis

wordpress.org/plugins/sequra

Flexible payment platform that enhances business conversion and recurrence. The easiest, safest, and quickest way for customers to pay installments.

900 active installs v4.2.0 PHP 7.3+ WP 5.9+ Updated Mar 24, 2026
bnplbuy-now-pay-laterinstallmentspayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is seQura Safe to Use in 2026?

Generally Safe

Score 100/100

seQura has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of the 'sequra' plugin v4.1.3 reveals a generally strong security posture, with no identified critical or high-severity code signals or taint flows. The plugin demonstrates good practices in output escaping, with 92% of outputs properly escaped, and a significant portion (67%) of its SQL queries utilizing prepared statements, which is a positive indicator of defense against SQL injection. Furthermore, there is no historical record of CVEs associated with this plugin, suggesting a relatively stable and secure development history. The lack of a large attack surface, particularly unprotected entry points, is also a significant strength.

However, there are areas that warrant attention. The complete absence of nonce checks and capability checks across all entry points is a notable concern. While the current analysis doesn't show any exploitable paths (0% unsanitized paths, 0 total flows analyzed), the lack of these fundamental security measures means that if a new vulnerability were introduced or discovered, it could potentially be exploited more easily. The presence of file operations also suggests potential interaction with the filesystem that, without proper checks, could be a vector for unauthorized modifications or information disclosure. The plugin's history of zero vulnerabilities, while positive, could also be an indicator that the plugin is not extensively tested or used, or that its attack surface is inherently limited, which might change with future updates or increased usage.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • File operations present without clear auth checks
  • Some SQL queries not prepared
  • Some outputs not properly escaped
Vulnerabilities
None known

seQura Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

seQura Release Timeline

v4.2.0Current
v4.1.3
v4.1.1
v4.1.0
v4.0.0
v3.2.2
v3.2.1
v3.2.0
v3.1.1
v3.1.0
v3.0.7
v3.0.6
v3.0.5
v3.0.2
v3.0.0
v2.0.12
v2.0.11
v2.0.10
v2.0.9
v2.0.8
Code Analysis
Analyzed Mar 16, 2026

seQura Code Analysis

Dangerous Functions
0
Raw SQL Queries
12
24 prepared
Unescaped Output
9
97 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared36 total queries

Output Escaping

92% escaped106 total outputs
Attack Surface

seQura Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

seQura Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 24, 2026
PHP min version7.3
Downloads16K

Community Trust

Rating100/100
Number of ratings2
Active installs900
Developer Profile

seQura Developer Profile

SeQura Tech

1 plugin · 900 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect seQura

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sequra/assets/css/admin.css/wp-content/plugins/sequra/assets/css/checkout.css/wp-content/plugins/sequra/assets/css/frontend.css/wp-content/plugins/sequra/assets/css/frontend.min.css/wp-content/plugins/sequra/assets/js/admin.js/wp-content/plugins/sequra/assets/js/admin.min.js/wp-content/plugins/sequra/assets/js/checkout.js/wp-content/plugins/sequra/assets/js/checkout.min.js+2 more
Script Paths
/wp-content/plugins/sequra/assets/js/admin.js/wp-content/plugins/sequra/assets/js/admin.min.js/wp-content/plugins/sequra/assets/js/checkout.js/wp-content/plugins/sequra/assets/js/checkout.min.js/wp-content/plugins/sequra/assets/js/frontend.js/wp-content/plugins/sequra/assets/js/frontend.min.js
Version Parameters
sequra/assets/css/admin.css?ver=sequra/assets/css/checkout.css?ver=sequra/assets/css/frontend.css?ver=sequra/assets/js/admin.js?ver=sequra/assets/js/checkout.js?ver=sequra/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
sequra-payment-gatewaysequra-checkout-formsequra-widget-containersequra-product-widgetsequra-cart-widgetsequra-product-listing-widgetsequra-meta-boxsequra-settings-page+2 more
HTML Comments
<!-- seQura payment gateway --><!-- seQura widget starts --><!-- seQura widget ends --><!-- seQura cart widget starts -->+3 more
Data Attributes
data-sequra-payment-iddata-sequra-widget-typedata-sequra-product-iddata-sequra-cart-id
JS Globals
sequra_admin_paramssequra_checkout_paramssequra_frontend_paramsSeQuraWidget
REST Endpoints
/wp-json/sequra/v1/settings/wp-json/sequra/v1/onboarding/wp-json/sequra/v1/payment/wp-json/sequra/v1/logs
Shortcode Output
[sequra_widget][sequra_cart_widget][sequra_product_listing_widget]
FAQ

Frequently Asked Questions about seQura