
Smjrifle QR Payments Security & Risk Analysis
wordpress.org/plugins/smjrifle-qr-paymentsAccept QR payments in WooCommerce. Customers scan, pay, and upload receipt for manual verification.
Is Smjrifle QR Payments Safe to Use in 2026?
Generally Safe
Score 100/100Smjrifle QR Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "smjrifle-qr-payments" v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and performs a high percentage of output escaping. The absence of known vulnerabilities in its history and no recorded critical or high severity taint flows are also encouraging indicators. However, significant concerns arise from the plugin's attack surface. With two identified AJAX handlers, both lacking authentication checks, and zero capability checks, this creates a substantial risk of unauthorized access and potential exploitation of these entry points. The single file operation also warrants attention, though without further context, its specific risk is unknown. The lack of nonce checks on one of the AJAX handlers is a significant oversight.
Overall, while the plugin has good internal code hygiene for SQL and output handling, its external-facing entry points are poorly secured. The two unprotected AJAX handlers represent the most immediate and critical security concern. The absence of capability checks on any functionality is a major weakness that could allow unauthenticated users to trigger sensitive actions. The plugin's vulnerability history is clean, suggesting it has not been a target or has had its issues addressed promptly in the past, but this cannot excuse the present security gaps. Future development should prioritize implementing robust authentication and authorization mechanisms for all entry points.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without capability checks
- Missing nonce checks on AJAX handler
- Unescaped output (6% of total)
Smjrifle QR Payments Security Vulnerabilities
Smjrifle QR Payments Release Timeline
Smjrifle QR Payments Code Analysis
Output Escaping
Smjrifle QR Payments Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Smjrifle QR Payments Maintenance & Trust
Maintenance Signals
Community Trust
Smjrifle QR Payments Alternatives
No alternatives data available yet.
Smjrifle QR Payments Developer Profile
3 plugins · 10 total installs
How We Detect Smjrifle QR Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smjrifle-qr-payments/admin/css/smjrifle-qr-payments-admin.css/wp-content/plugins/smjrifle-qr-payments/admin/js/smjrifle-qr-payments-admin.js/wp-content/plugins/smjrifle-qr-payments/public/css/smjrifle-qr-payments-public.css/wp-content/plugins/smjrifle-qr-payments/public/js/smjrifle-qr-payments-public.js/wp-content/plugins/smjrifle-qr-payments/admin/js/smjrifle-qr-payments-admin.js/wp-content/plugins/smjrifle-qr-payments/public/js/smjrifle-qr-payments-public.jssmjrifle-qr-payments/admin/css/smjrifle-qr-payments-admin.css?ver=smjrifle-qr-payments/admin/js/smjrifle-qr-payments-admin.js?ver=smjrifle-qr-payments/public/css/smjrifle-qr-payments-public.css?ver=smjrifle-qr-payments/public/js/smjrifle-qr-payments-public.js?ver=HTML / DOM Fingerprints
data-smjrifle-qr-payments-upload-noncesmjrifle_qr_payments_params/wp-json/smjrifle-qr-payments/v1/upload