Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Security & Risk Analysis

wordpress.org/plugins/snappay-alipay-wechat-payment-gateway

Allow Canadian merchants to easily accept Wechat Pay, Alipay and UnionPay for their websites using SnapPay's payment gateway.

100 active installs v2.3.3 PHP + WP 4.0+ Updated Jan 18, 2023
alipaycadunionpayusdwechat-pay
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'snappay-alipay-wechat-payment-gateway' plugin v2.3.3 exhibits a mixed security posture. On the positive side, the static analysis shows no identified dangerous functions, all SQL queries utilize prepared statements, and there are no known vulnerabilities (CVEs) associated with this plugin. This suggests a level of diligence in secure coding practices, particularly regarding database interactions and the absence of historical exploits.

However, several areas raise concerns. The low percentage of properly escaped output (27%) indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of file operations and external HTTP requests without clear context on their security handling warrants further investigation, as these can be vectors for attack if not properly validated and sanitized. The lack of nonce and capability checks on the identified entry points, though the total number is zero, means that if any were to be introduced in future updates or if the analysis missed them, they would be unprotected. The bundled outdated jQuery library, while common, can also introduce known vulnerabilities if not updated or if its functionalities are used in an insecure manner.

Overall, while the plugin benefits from a clean vulnerability history and secure SQL handling, the prevalent lack of output escaping and the presence of potentially sensitive operations like file and external HTTP requests without explicit checks are significant weaknesses. The absence of identified taint flows and entry points is encouraging but doesn't entirely negate the risks posed by unescaped output and potential misconfigurations of file/HTTP operations.

Key Concerns

  • Low output escaping percentage
  • Bundled outdated jQuery library
  • File operations without clear checks
  • External HTTP requests without clear checks
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

jQuery3.4.1

Output Escaping

27% escaped11 total outputs
Attack Surface

Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwoocommerce_update_options_payment_gatewaysclass-wc-snappay-gateway.php:33
actionwoocommerce_api_wc_snappay_notifyclass-wc-snappay-gateway.php:36
actionwoocommerce_checkout_update_order_metaclass-wc-snappay-gateway.php:37
actionwoocommerce_thankyouclass-wc-snappay-gateway.php:38
actionplugins_loadedsnappaymain.php:34
filterwoocommerce_payment_gatewayssnappaymain.php:41
actioninitsnappaymain.php:60
filterheartbeat_settingssnappaymain.php:65
filterheartbeat_receivedsnappaymain.php:71
filterheartbeat_nopriv_receivedsnappaymain.php:72
actionwoocommerce_admin_order_data_after_billing_addresssnappaymain.php:91
Maintenance & Trust

Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 18, 2023
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版) Developer Profile

SnapPay

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snappay-alipay-wechat-payment-gateway/css/snappay_checkout.css/wp-content/plugins/snappay-alipay-wechat-payment-gateway/js/snappay_gateway.js
Script Paths
/wp-content/plugins/snappay-alipay-wechat-payment-gateway/js/snappay_gateway.js
Version Parameters
snappay-alipay-wechat-payment-gateway/css/snappay_checkout.css?ver=snappay-alipay-wechat-payment-gateway/js/snappay_gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
snappay-payment-button
HTML Comments
<!-- SnapPay Gateway --><!-- SnapPay Admin Options -->
Data Attributes
data-snappay-merchant-iddata-snappay-app-iddata-snappay-sign-keydata-snappay-currencydata-snappay-order-iddata-snappay-amount+3 more
JS Globals
window.SnappayGatewayConfig
REST Endpoints
/wp-json/snappay/v1/notify
FAQ

Frequently Asked Questions about Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版)