Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Security & Risk Analysis

wordpress.org/plugins/simpaisa-wallet-payment-services

Providing Easy To Integrate Jazzcash & Easypaisa Digital Payment Services.

1K active installs v2.1.6 PHP 5.4+ WP 4.4+ Updated Dec 8, 2023
easypaisajazzcashsimpaisawalletwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Safe to Use in 2026?

Generally Safe

Score 85/100

Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The simpaisa-wallet-payment-services v2.1.6 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs, no dangerous functions, and all SQL queries utilize prepared statements, indicating good practices in these areas. The plugin also avoids bundling external libraries and makes a limited number of external HTTP requests. However, there are significant concerns regarding output escaping and taint analysis. A low percentage of outputs are properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. Furthermore, the taint analysis reveals flows with unsanitized paths, although no critical or high severity issues were identified in this analysis. The complete lack of nonce checks and capability checks, coupled with zero unprotected entry points (AJAX, REST API, shortcodes, cron events), is a contradictory signal. While it suggests these components might not be directly exposed or used in a way that requires them, it could also indicate a lack of robust input validation and authorization mechanisms if these components are indeed active and handling sensitive data. The absence of vulnerability history is a positive sign, but it does not negate the risks identified in the code analysis.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

31% escaped16 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
simpaisa_jz_ep_wallet_init_gateway_class (simpaisa-wallet-payment-services.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filterwoocommerce_payment_gatewayssimpaisa-wallet-payment-services.php:13
actionplugins_loadedsimpaisa-wallet-payment-services.php:23
actionwp_enqueue_scriptssimpaisa-wallet-payment-services.php:50
actionwp_enqueue_scriptssimpaisa-wallet-payment-services.php:51
actionwoocommerce_api_simpaisa_wallet_redirectsimpaisa-wallet-payment-services.php:55
actionwoocommerce_api_simpaisa_wallet_get_payment_detailssimpaisa-wallet-payment-services.php:57
actionwoocommerce_api_simpaisa_wallet_order_verifysimpaisa-wallet-payment-services.php:59
actionwoocommerce_api_simpaisa_notifysimpaisa-wallet-payment-services.php:62
actionadmin_noticessimpaisa-wallet-payment-services.php:577
actionadmin_noticessimpaisa-wallet-payment-services.php:580
Maintenance & Trust

Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 8, 2023
PHP min version5.4
Downloads24K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services Developer Profile

Maqsood Ali

2 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simpaisa-wallet-payment-services/assets/easypaisa-logo.png/wp-content/plugins/simpaisa-wallet-payment-services/assets/jazzcash-logo.png

HTML / DOM Fingerprints

CSS Classes
simpaisa-jazz-easy-cardsimpaisa-jazz-easy-card-headersimpaisa-jazz-easy-navsimpaisa-jazz-easy-nav-tabssimpaisa-jazz-easy-nav-itemsimpaisa-jazz-easy-nav-linksimpaisa-jazz-easy-paymentgateway_logossimpaisa-jazz-easy-card-hr+2 more
Data Attributes
sp_wallet_account_typesp_wallet_account
REST Endpoints
/wp-json/simpaisa/v1/notify/wp-json/simpaisa/v1/order_verify/wp-json/simpaisa/v1/get_payment_details/wp-json/simpaisa/v1/redirect
FAQ

Frequently Asked Questions about Simpaisa Wallet (Jazzcash & Easypaisa) Payment Services