
SmobilPay for e-commerce Gateway for Easy Digital Downloads Security & Risk Analysis
wordpress.org/plugins/smobilplay-edd-gatewaySmobilPay Easy Digital Downloads is a secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or w …
Is SmobilPay for e-commerce Gateway for Easy Digital Downloads Safe to Use in 2026?
Generally Safe
Score 85/100SmobilPay for e-commerce Gateway for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The smobilplay-edd-gateway plugin v1.0.2 presents a mixed security posture. On the positive side, it exhibits good practices by not using dangerous functions, performing file operations, or making external HTTP requests. The plugin also demonstrates a high percentage of properly escaped output and a reasonable approach to SQL queries with a 50% use of prepared statements. Its vulnerability history is currently clean, with no recorded CVEs, suggesting a potentially well-maintained or less targeted codebase.
However, significant concerns arise from the attack surface analysis. The plugin exposes two REST API routes that lack permission callbacks, meaning they are accessible without any authentication or authorization checks. This represents a critical security weakness, as any unauthenticated user could potentially interact with these endpoints, leading to unintended consequences or data exposure depending on their functionality. While the static analysis did not reveal specific taint flows or dangerous functions, the lack of access control on these entry points is a substantial risk that requires immediate attention.
In conclusion, while the plugin adheres to some good security principles, the presence of unprotected REST API routes is a critical flaw that outweighs its strengths. The absence of known vulnerabilities is a positive sign, but it does not mitigate the inherent risk posed by unauthenticated entry points. Addressing these unprotected routes should be the highest priority for improving the plugin's security.
Key Concerns
- Unprotected REST API routes
- REST API routes without permission callbacks
- SQL queries with lack of prepared statements
- Bundled libraries (Guzzle) may be outdated
SmobilPay for e-commerce Gateway for Easy Digital Downloads Security Vulnerabilities
SmobilPay for e-commerce Gateway for Easy Digital Downloads Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SmobilPay for e-commerce Gateway for Easy Digital Downloads Attack Surface
REST API Routes 2
WordPress Hooks 15
Maintenance & Trust
SmobilPay for e-commerce Gateway for Easy Digital Downloads Maintenance & Trust
Maintenance Signals
Community Trust
SmobilPay for e-commerce Gateway for Easy Digital Downloads Alternatives
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce
e-nkap-woocommerce-gateway
A secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or website
SoleasPay payment gateway for WooCommerce
soleaspay-payment-gateway-for-woocommerce
SoleasPay - Payment gateway for WooCommerce
Direct Payments for WooCommerce – Bank Transfer, Mobile Money, Crypto and Peer-to-Peer (P2P) Payments
direct-payments-for-woocommerce
Direct Payments for WooCommerce allows your store to accept instant payments via bank transfers, mobile money, crypto and popular P2P platforms global …
Campay Woocommerce Payment Gateway
campay-api
CamPay is a Fintech service of the company TAKWID
UnitechPay – Wave & Orange Money Payments
unitechpay-paiements-mobile-money
Solution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !
SmobilPay for e-commerce Gateway for Easy Digital Downloads Developer Profile
1 plugin · 0 total installs
How We Detect SmobilPay for e-commerce Gateway for Easy Digital Downloads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smobilplay-edd-gateway/assets/images/e-nkap.pngHTML / DOM Fingerprints
edd_enkap_purchase_merchant_refedd_enkap_purchase_transaction_iddata-enkap-orderdata-enkap-refEnkap_data/wp-json/enkap/v1/notification/wp-json/enkap/v1/return