SmobilPay for e-commerce Gateway for Easy Digital Downloads Security & Risk Analysis

wordpress.org/plugins/smobilplay-edd-gateway

SmobilPay Easy Digital Downloads is a secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or w …

0 active installs v1.0.2 PHP 7.3+ WP 4.7+ Updated Nov 16, 2021
gatewaymobile-moneyorange-moneypayment-aggregatorwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SmobilPay for e-commerce Gateway for Easy Digital Downloads Safe to Use in 2026?

Generally Safe

Score 85/100

SmobilPay for e-commerce Gateway for Easy Digital Downloads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The smobilplay-edd-gateway plugin v1.0.2 presents a mixed security posture. On the positive side, it exhibits good practices by not using dangerous functions, performing file operations, or making external HTTP requests. The plugin also demonstrates a high percentage of properly escaped output and a reasonable approach to SQL queries with a 50% use of prepared statements. Its vulnerability history is currently clean, with no recorded CVEs, suggesting a potentially well-maintained or less targeted codebase.

However, significant concerns arise from the attack surface analysis. The plugin exposes two REST API routes that lack permission callbacks, meaning they are accessible without any authentication or authorization checks. This represents a critical security weakness, as any unauthenticated user could potentially interact with these endpoints, leading to unintended consequences or data exposure depending on their functionality. While the static analysis did not reveal specific taint flows or dangerous functions, the lack of access control on these entry points is a substantial risk that requires immediate attention.

In conclusion, while the plugin adheres to some good security principles, the presence of unprotected REST API routes is a critical flaw that outweighs its strengths. The absence of known vulnerabilities is a positive sign, but it does not mitigate the inherent risk posed by unauthenticated entry points. Addressing these unprotected routes should be the highest priority for improving the plugin's security.

Key Concerns

  • Unprotected REST API routes
  • REST API routes without permission callbacks
  • SQL queries with lack of prepared statements
  • Bundled libraries (Guzzle) may be outdated
Vulnerabilities
None known

SmobilPay for e-commerce Gateway for Easy Digital Downloads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SmobilPay for e-commerce Gateway for Easy Digital Downloads Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
4 prepared
Unescaped Output
4
39 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

50% prepared8 total queries

Output Escaping

91% escaped43 total outputs
Attack Surface
2 unprotected

SmobilPay for e-commerce Gateway for Easy Digital Downloads Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

GET/wp-json/edd-e-nkap/return/(.*?)includes\Gateway.php:492
PUT/wp-json/edd-e-nkap/notification/(.*?)includes\Gateway.php:514
WordPress Hooks 15
filteredd_settings_gatewaysincludes\Gateway.php:45
filteredd_view_order_details_payment_meta_afterincludes\Gateway.php:46
filteredd_purchase_history_header_afterincludes\Gateway.php:47
actionedd_purchase_history_row_endincludes\Gateway.php:48
actionadmin_initincludes\Gateway.php:49
actionadmin_post_edd_enkap_mark_order_statusincludes\Gateway.php:50
filteredd_accepted_payment_iconsincludes\Gateway.php:55
filteredd_payment_gatewaysincludes\Gateway.php:56
filteredd_settings_sections_gatewaysincludes\Gateway.php:57
actionrest_api_initincludes\Gateway.php:59
actionrest_api_initincludes\Gateway.php:60
actionwpmu_new_blogincludes\Install.php:13
filterwpmu_drop_tablesincludes\Install.php:14
actionplugins_loadedincludes\Plugin.php:58
actioninitincludes\Plugin.php:68
Maintenance & Trust

SmobilPay for e-commerce Gateway for Easy Digital Downloads Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 16, 2021
PHP min version7.3
Downloads998

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SmobilPay for e-commerce Gateway for Easy Digital Downloads Developer Profile

smobilpay

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SmobilPay for e-commerce Gateway for Easy Digital Downloads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smobilplay-edd-gateway/assets/images/e-nkap.png

HTML / DOM Fingerprints

CSS Classes
edd_enkap_purchase_merchant_refedd_enkap_purchase_transaction_id
Data Attributes
data-enkap-orderdata-enkap-ref
JS Globals
Enkap_data
REST Endpoints
/wp-json/enkap/v1/notification/wp-json/enkap/v1/return
FAQ

Frequently Asked Questions about SmobilPay for e-commerce Gateway for Easy Digital Downloads