
StarPay-WPP Plugin Security & Risk Analysis
wordpress.org/plugins/starpay-wppStarPay mpm and online payment gateway. Support China and Japan mainstream payment methods.
Is StarPay-WPP Plugin Safe to Use in 2026?
Generally Safe
Score 85/100StarPay-WPP Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The starpay-wpp plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, indicating a resistance to SQL injection vulnerabilities. The absence of known CVEs and a lack of recorded vulnerabilities in its history are also encouraging signs, suggesting a relatively stable and well-maintained codebase.
However, significant security concerns arise from the static analysis. The plugin exposes two REST API routes that lack permission callbacks, creating an open attack surface for unauthorized access and potential manipulation of plugin functionalities. Furthermore, the taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity by the tool, represent potential vectors for injection attacks if malicious data is passed through these flows. The lack of nonce checks on AJAX handlers, coupled with the presence of file operations and external HTTP requests, further increases the potential for vulnerabilities if these entry points are not properly secured.
In conclusion, while the plugin has a clean vulnerability history and good SQL practices, the unprotected REST API routes and unsanitized taint flows present clear and actionable risks. These areas require immediate attention to mitigate potential security breaches. The plugin's overall security could be significantly improved by implementing proper authorization checks on its REST API endpoints and thoroughly sanitizing all data flowing through the identified tainted paths.
Key Concerns
- REST API routes without permission callbacks
- Taint flows with unsanitized paths
- No nonce checks on AJAX handlers
- Insufficient output escaping (56% proper)
StarPay-WPP Plugin Security Vulnerabilities
StarPay-WPP Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
StarPay-WPP Plugin Attack Surface
REST API Routes 2
WordPress Hooks 14
Maintenance & Trust
StarPay-WPP Plugin Maintenance & Trust
Maintenance Signals
Community Trust
StarPay-WPP Plugin Alternatives
China Payments Plugin | Accept WeChat Pay, Alipay & UnionPay | Chinese Checkout Optimization
wp-stripe-global-payments
Accept WeChat Pay, Alipay & UnionPay via Stripe. Chinese checkout optimization with localization, multi-currency display & CNY conversion for …
Yedpay for WooCommerce
yedpay-for-woocommerce
Easily accept Alipay, AlipayHK, Wechat Pay, UnionPay, Visa and mastercard on your Wordpress site using Yedpay WooCommerce payment gateway in one plugi …
Payment Gateway for Alipay and WeChat Pay (支付宝,微信支付,银联支付北美版)
snappay-alipay-wechat-payment-gateway
Allow Canadian merchants to easily accept Wechat Pay, Alipay and UnionPay for their websites using SnapPay's payment gateway.
AlphaPay for WeChat Pay, Alipay, UnionPay, and Credit Card(微信支付,支付宝,银联,信用卡支付)
alpha-pay-wechat-pay-alipay-for-woocommerce
Allow Canadian merchants to connect all the mainstream payment channels like WeChat Pay, Alipay, UnionPay, Visa, and MasterCard upon single activation …
Wenprise WeChatPay Payment Gateway For WooCommerce
wenprise-wechatpay-checkout-for-woocommerce
WeChat payment gateway for WooCommerce, WooCommerce 微信免费全功能支付网关。
StarPay-WPP Plugin Developer Profile
1 plugin · 0 total installs
How We Detect StarPay-WPP Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/starpay-wpp/js/jquery.qrcode.min.js/wp-content/plugins/starpay-wpp/js/jquery.qrcode.min.jsHTML / DOM Fingerprints
/starpay/v1/recpayresult/starpay/v1/recbackresult