
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Security & Risk Analysis
wordpress.org/plugins/thanh-toan-chuyen-khoanTích hợp thanh toán quét mã QR Code với MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Is Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Safe to Use in 2026?
Generally Safe
Score 92/100Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin, thanh-toan-chuyen-khoan v1.0.0, presents a significant security risk due to its large, unprotected attack surface. All seven identified entry points, including six AJAX handlers and one REST API route, lack proper authentication and permission checks. This means any unauthenticated user could potentially interact with these functions, leading to unintended actions or data exposure. While the code demonstrates good practices in SQL query handling, using prepared statements exclusively, the output escaping is a concern with 40% of outputs not properly sanitized, creating a potential for cross-site scripting (XSS) vulnerabilities. The presence of unsanitized paths in taint analysis, even without critical or high severity findings, further reinforces the risk of path traversal or unauthorized file access. The absence of any recorded vulnerability history might suggest a lack of prior exploitation or discovery, but this should not be relied upon as a measure of current security. The plugin's strengths lie in its SQL practices and the absence of dangerous functions, but these are heavily outweighed by the critical lack of input validation and authorization on its exposed interfaces.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Output escaping (60% properly escaped)
- Flows with unsanitized paths
- File operations detected
- External HTTP requests detected
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Security Vulnerabilities
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 17
Maintenance & Trust
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Maintenance & Trust
Maintenance Signals
Community Trust
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Alternatives
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam
bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang
Tích hợp thanh toán quét mã QR Code MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng
casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang
Kết nối các ngân hàng Việt Nam vào Woocommerce, tự động xác nhận đơn hàng đã thanh toán. Hỗ trợ hơn 10 ngân hàng : VietinBank, OCB, Vietcombank, Techc …
Tích hợp Thanh Toán Quét Mã QR Code – MoMo, ViettelPay, Vietcombank
qh-testpay
Tích hợp thanh toán quét mã QR Code với MoMo, ViettelPay, VNPay, Vietcombank, Vietinbank, Techcombank, MB, ACB, VPBank, TPBank.. cho Woocommerce
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV Developer Profile
1 plugin · 80 total installs
How We Detect Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, MB, Vietcombank, Vietinbank, Techcombank, Agribank, ACB, BIDV
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/thanh-toan-chuyen-khoan/assets/css/style.css/wp-content/plugins/thanh-toan-chuyen-khoan/assets/js/easy.qrcode.js/wp-content/plugins/thanh-toan-chuyen-khoan/assets/js/js.js/wp-content/plugins/thanh-toan-chuyen-khoan/assets/js/easy.qrcode.js/wp-content/plugins/thanh-toan-chuyen-khoan/assets/js/js.jsthanh-toan-chuyen-khoan/assets/css/style.css?ver=thanh-toan-chuyen-khoan/assets/js/easy.qrcode.js?ver=thanh-toan-chuyen-khoan/assets/js/js.js?ver=HTML / DOM Fingerprints
TTCK_DIRTTCK_URLTTCK_TESTTTCKPayment/wp-json/ttck/v1/auth_sync_status/wp-json/ttck/v1/fetch_order_status/wp-json/ttck/v1/paid_order