Smjrifle QR Payments Security & Risk Analysis

wordpress.org/plugins/smjrifle-qr-payments

Accept QR payments in WooCommerce. Customers scan, pay, and upload receipt for manual verification.

10 active installs v1.0.2 PHP 7.4+ WP 5.6+ Updated Mar 28, 2026
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Smjrifle QR Payments Safe to Use in 2026?

Generally Safe

Score 100/100

Smjrifle QR Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "smjrifle-qr-payments" v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and performs a high percentage of output escaping. The absence of known vulnerabilities in its history and no recorded critical or high severity taint flows are also encouraging indicators. However, significant concerns arise from the plugin's attack surface. With two identified AJAX handlers, both lacking authentication checks, and zero capability checks, this creates a substantial risk of unauthorized access and potential exploitation of these entry points. The single file operation also warrants attention, though without further context, its specific risk is unknown. The lack of nonce checks on one of the AJAX handlers is a significant oversight.

Overall, while the plugin has good internal code hygiene for SQL and output handling, its external-facing entry points are poorly secured. The two unprotected AJAX handlers represent the most immediate and critical security concern. The absence of capability checks on any functionality is a major weakness that could allow unauthenticated users to trigger sensitive actions. The plugin's vulnerability history is clean, suggesting it has not been a target or has had its issues addressed promptly in the past, but this cannot excuse the present security gaps. Future development should prioritize implementing robust authentication and authorization mechanisms for all entry points.

Key Concerns

  • AJAX handlers without authentication checks
  • AJAX handlers without capability checks
  • Missing nonce checks on AJAX handler
  • Unescaped output (6% of total)
Vulnerabilities
None known

Smjrifle QR Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Smjrifle QR Payments Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Smjrifle QR Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
60 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped64 total outputs
Attack Surface
2 unprotected

Smjrifle QR Payments Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_smjrifle_qr_payments_uploadincludes\class-smjrifle-qr-payments.php:46
noprivwp_ajax_smjrifle_qr_payments_uploadincludes\class-smjrifle-qr-payments.php:47
WordPress Hooks 10
actionadd_meta_boxesadmin\class-smjrifle-qr-payments-admin.php:18
actionwoocommerce_email_order_metaadmin\class-smjrifle-qr-payments-admin.php:19
actionadmin_enqueue_scriptsincludes\class-smjrifle-qr-payments.php:34
actionadmin_enqueue_scriptsincludes\class-smjrifle-qr-payments.php:35
actionadd_meta_boxesincludes\class-smjrifle-qr-payments.php:36
actionwp_enqueue_scriptsincludes\class-smjrifle-qr-payments.php:43
actionwp_enqueue_scriptsincludes\class-smjrifle-qr-payments.php:44
actionplugins_loadedincludes\class-smjrifle-qr-payments.php:53
filterwoocommerce_payment_gatewaysincludes\class-smjrifle-qr-payments.php:63
filterupload_dirpublic\class-smjrifle-qr-payments-public.php:89
Maintenance & Trust

Smjrifle QR Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMar 28, 2026
PHP min version7.4
Downloads446

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Smjrifle QR Payments Alternatives

No alternatives data available yet.

Developer Profile

Smjrifle QR Payments Developer Profile

smjrifle

3 plugins · 10 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smjrifle QR Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smjrifle-qr-payments/admin/css/smjrifle-qr-payments-admin.css/wp-content/plugins/smjrifle-qr-payments/admin/js/smjrifle-qr-payments-admin.js/wp-content/plugins/smjrifle-qr-payments/public/css/smjrifle-qr-payments-public.css/wp-content/plugins/smjrifle-qr-payments/public/js/smjrifle-qr-payments-public.js
Script Paths
/wp-content/plugins/smjrifle-qr-payments/admin/js/smjrifle-qr-payments-admin.js/wp-content/plugins/smjrifle-qr-payments/public/js/smjrifle-qr-payments-public.js
Version Parameters
smjrifle-qr-payments/admin/css/smjrifle-qr-payments-admin.css?ver=smjrifle-qr-payments/admin/js/smjrifle-qr-payments-admin.js?ver=smjrifle-qr-payments/public/css/smjrifle-qr-payments-public.css?ver=smjrifle-qr-payments/public/js/smjrifle-qr-payments-public.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-smjrifle-qr-payments-upload-nonce
JS Globals
smjrifle_qr_payments_params
REST Endpoints
/wp-json/smjrifle-qr-payments/v1/upload
FAQ

Frequently Asked Questions about Smjrifle QR Payments