[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fl7gI6AnSmizSpYsn7bhEcvBhdnViBvhhLOid50b52K8":3,"$fMRL4To_PlsHTNzsL3h4UhIkr3pQmEGjWMdYLTGyjshs":144,"$fo0pnjDj9W9y1CHwsJw22twy6Ro6twqYr1OF0KuvrpmI":148},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":19,"download_link":20,"security_score":21,"vuln_count":13,"unpatched_count":13,"last_vuln_date":22,"fetched_at":23,"discovery_status":24,"vulnerabilities":25,"developer":26,"crawl_stats":22,"alternatives":32,"analysis":33,"fingerprints":120},"smjrifle-qr-payments","Smjrifle QR Payments","1.0.2","smjrifle","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmjrifle\u002F","\u003Cp>Smjrifle QR Payments for WooCommerce is a lightweight manual QR gateway built for stores that want zero commission and full control.\u003C\u002Fp>\n\u003Cp>Customers scan your QR code using their banking app, complete the transfer, and upload the receipt directly on the checkout page. Orders are placed on hold until you verify payment.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important Note on Dynamic QR:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe “Dynamic Merchant QR” mode requires an official Merchant QR string (EMV format). It will \u003Cstrong>not\u003C\u002Fstrong> work with generic “Personal” QR codes from standard banking apps. For personal accounts, please use the “Static Image” mode to upload your account’s QR screenshot.\u003C\u002Fp>\n\u003Cp>No third-party processors. No API dependency. No transaction fees.\u003C\u002Fp>\n\u003Cp>Built and maintained by Shailesh Man Joshi (smjrifle).\u003Cbr \u002F>\nSupport and updates: https:\u002F\u002Fsmjrifle.net\u002F\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Static QR image upload or Dynamic Merchant QR generation\u003C\u002Fli>\n\u003Cli>Inline checkout flow without redirects\u003C\u002Fli>\n\u003Cli>Optional bank transfer details display\u003C\u002Fli>\n\u003Cli>Drag and drop receipt upload\u003C\u002Fli>\n\u003Cli>Secure AJAX upload with nonce validation\u003C\u002Fli>\n\u003Cli>Place Order locked until receipt is uploaded (classic checkout)\u003C\u002Fli>\n\u003Cli>Receipt preview inside WooCommerce admin\u003C\u002Fli>\n\u003Cli>Orders set to On Hold for manual verification\u003C\u002Fli>\n\u003Cli>Zero commission payments\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Customer selects QR Payment at checkout.\u003C\u002Fli>\n\u003Cli>QR code is displayed with payment instructions.\u003C\u002Fli>\n\u003Cli>Customer completes payment in their banking app.\u003C\u002Fli>\n\u003Cli>Customer uploads receipt.\u003C\u002Fli>\n\u003Cli>Order is placed on hold.\u003C\u002Fli>\n\u003Cli>Admin verifies and updates order status.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Dynamic QR Requirements:\u003C\u002Fstrong>\u003Cbr \u002F>\n* This mode requires a \u003Cstrong>Merchant Account\u003C\u002Fstrong> QR code.\u003Cbr \u002F>\n* To set up: Scan your merchant board with a generic scanner (like Google Lens).\u003Cbr \u002F>\n* Copy the full raw text (Format: \u003Ccode>00020101021226...\u003C\u002Fcode>).\u003Cbr \u002F>\n* Paste it into the plugin settings.\u003Cbr \u002F>\n* If your QR text does not start with \u003Ccode>000201\u003C\u002Fcode>, it is likely a personal QR and you should use \u003Cstrong>Static Image Mode\u003C\u002Fstrong> instead.\u003C\u002Fp>\n","Accept QR payments in WooCommerce. Customers scan, pay, and upload receipt for manual verification.",10,446,0,"2026-03-28T12:11:00.000Z","6.9.5","5.6","7.4",[],"","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsmjrifle-qr-payments.1.0.2.zip",100,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":27,"total_installs":11,"avg_security_score":28,"avg_patch_time_days":29,"trust_score":30,"computed_at":31},3,93,30,89,"2026-08-29T16:38:18.447Z",[],{"attackSurface":34,"codeSignals":87,"taintFlows":106,"riskAssessment":107,"analyzedAt":119},{"hooks":35,"ajaxHandlers":74,"restRoutes":83,"shortcodes":84,"cronEvents":85,"entryPointCount":86,"unprotectedCount":86},[36,42,46,51,54,56,59,61,65,70],{"type":37,"name":38,"callback":39,"priority":11,"file":40,"line":41},"action","add_meta_boxes","add_meta_box","admin\\class-smjrifle-qr-payments-admin.php",18,{"type":37,"name":43,"callback":44,"priority":11,"file":40,"line":45},"woocommerce_email_order_meta","receipt_email_meta",19,{"type":37,"name":47,"callback":48,"file":49,"line":50},"admin_enqueue_scripts","enqueue_styles","includes\\class-smjrifle-qr-payments.php",34,{"type":37,"name":47,"callback":52,"file":49,"line":53},"enqueue_scripts",35,{"type":37,"name":38,"callback":39,"file":49,"line":55},36,{"type":37,"name":57,"callback":48,"file":49,"line":58},"wp_enqueue_scripts",43,{"type":37,"name":57,"callback":52,"file":49,"line":60},44,{"type":37,"name":62,"callback":63,"file":49,"line":64},"plugins_loaded","init_gateway",53,{"type":66,"name":67,"callback":68,"file":49,"line":69},"filter","woocommerce_payment_gateways","add_gateway",63,{"type":66,"name":71,"callback":72,"file":73,"line":30},"upload_dir","custom_upload_dir","public\\class-smjrifle-qr-payments-public.php",[75,80],{"action":76,"nopriv":77,"callback":78,"hasNonce":77,"hasCapCheck":77,"file":49,"line":79},"smjrifle_qr_payments_upload",false,"handle_upload",46,{"action":76,"nopriv":81,"callback":78,"hasNonce":77,"hasCapCheck":77,"file":49,"line":82},true,47,[],[],[],2,{"dangerousFunctions":88,"sqlUsage":89,"outputEscaping":91,"fileOperations":104,"externalRequests":13,"nonceChecks":104,"capabilityChecks":13,"bundledLibraries":105},[],{"prepared":13,"raw":13,"locations":90},[],{"escaped":92,"rawEcho":93,"locations":94},60,4,[95,98,100,102],{"file":40,"line":96,"context":97},110,"raw output",{"file":40,"line":99,"context":97},113,{"file":40,"line":101,"context":97},116,{"file":40,"line":103,"context":97},120,1,[],[],{"summary":108,"deductions":109},"The plugin \"smjrifle-qr-payments\" v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and performs a high percentage of output escaping.  The absence of known vulnerabilities in its history and no recorded critical or high severity taint flows are also encouraging indicators. However, significant concerns arise from the plugin's attack surface. With two identified AJAX handlers, both lacking authentication checks, and zero capability checks, this creates a substantial risk of unauthorized access and potential exploitation of these entry points. The single file operation also warrants attention, though without further context, its specific risk is unknown. The lack of nonce checks on one of the AJAX handlers is a significant oversight.\n\nOverall, while the plugin has good internal code hygiene for SQL and output handling, its external-facing entry points are poorly secured. The two unprotected AJAX handlers represent the most immediate and critical security concern. The absence of capability checks on any functionality is a major weakness that could allow unauthenticated users to trigger sensitive actions.  The plugin's vulnerability history is clean, suggesting it has not been a target or has had its issues addressed promptly in the past, but this cannot excuse the present security gaps. Future development should prioritize implementing robust authentication and authorization mechanisms for all entry points.",[110,112,114,117],{"reason":111,"points":11},"AJAX handlers without authentication checks",{"reason":113,"points":11},"AJAX handlers without capability checks",{"reason":115,"points":116},"Missing nonce checks on AJAX handler",7,{"reason":118,"points":27},"Unescaped output (6% of total)","2026-03-17T06:13:22.072Z",{"wat":121,"direct":134},{"assetPaths":122,"generatorPatterns":127,"scriptPaths":128,"versionParams":129},[123,124,125,126],"\u002Fwp-content\u002Fplugins\u002Fsmjrifle-qr-payments\u002Fadmin\u002Fcss\u002Fsmjrifle-qr-payments-admin.css","\u002Fwp-content\u002Fplugins\u002Fsmjrifle-qr-payments\u002Fadmin\u002Fjs\u002Fsmjrifle-qr-payments-admin.js","\u002Fwp-content\u002Fplugins\u002Fsmjrifle-qr-payments\u002Fpublic\u002Fcss\u002Fsmjrifle-qr-payments-public.css","\u002Fwp-content\u002Fplugins\u002Fsmjrifle-qr-payments\u002Fpublic\u002Fjs\u002Fsmjrifle-qr-payments-public.js",[],[124,126],[130,131,132,133],"smjrifle-qr-payments\u002Fadmin\u002Fcss\u002Fsmjrifle-qr-payments-admin.css?ver=","smjrifle-qr-payments\u002Fadmin\u002Fjs\u002Fsmjrifle-qr-payments-admin.js?ver=","smjrifle-qr-payments\u002Fpublic\u002Fcss\u002Fsmjrifle-qr-payments-public.css?ver=","smjrifle-qr-payments\u002Fpublic\u002Fjs\u002Fsmjrifle-qr-payments-public.js?ver=",{"cssClasses":135,"htmlComments":136,"htmlAttributes":137,"restEndpoints":139,"jsGlobals":141,"shortcodeOutput":143},[],[],[138],"data-smjrifle-qr-payments-upload-nonce",[140],"\u002Fwp-json\u002Fsmjrifle-qr-payments\u002Fv1\u002Fupload",[142],"smjrifle_qr_payments_params",[],{"error":81,"url":145,"statusCode":146,"statusMessage":147,"message":147},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fsmjrifle-qr-payments\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":27,"versions":149},[150,155,162],{"version":6,"download_url":20,"svn_tag_url":151,"released_at":22,"has_diff":77,"diff_files_changed":152,"diff_lines":22,"trac_diff_url":153,"vulnerabilities":154,"is_current":81},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsmjrifle-qr-payments\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsmjrifle-qr-payments%2Ftags%2F1.0.1&new_path=%2Fsmjrifle-qr-payments%2Ftags%2F1.0.2",[],{"version":156,"download_url":157,"svn_tag_url":158,"released_at":22,"has_diff":77,"diff_files_changed":159,"diff_lines":22,"trac_diff_url":160,"vulnerabilities":161,"is_current":77},"1.0.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsmjrifle-qr-payments.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsmjrifle-qr-payments\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fsmjrifle-qr-payments%2Ftags%2F1.0.0&new_path=%2Fsmjrifle-qr-payments%2Ftags%2F1.0.1",[],{"version":163,"download_url":164,"svn_tag_url":165,"released_at":22,"has_diff":77,"diff_files_changed":166,"diff_lines":22,"trac_diff_url":22,"vulnerabilities":167,"is_current":77},"1.0.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsmjrifle-qr-payments.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fsmjrifle-qr-payments\u002Ftags\u002F1.0.0\u002F",[],[]]