
Tilopay Security & Risk Analysis
wordpress.org/plugins/tilopayAccept payments on WooCommerce stores with seamless integration, multi-currency support, and advanced tools for secure payment processing.
Is Tilopay Safe to Use in 2026?
Generally Safe
Score 100/100Tilopay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tilopay" plugin v3.1.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, and having a high percentage of properly escaped output. Furthermore, its vulnerability history is clean, with no known CVEs, suggesting a generally well-maintained codebase.
However, significant concerns arise from the identified attack surface. The plugin has one unprotected REST API route, which represents a direct entry point for attackers without any authorization checks. The taint analysis also revealed two flows with unsanitized paths, indicating a potential for directory traversal or similar vulnerabilities, although their severity is not classified as critical or high in this analysis. The absence of capability checks on any of its entry points is a notable weakness.
In conclusion, while the plugin's core coding practices for data handling and SQL interaction are strong, the unprotected REST API route and the presence of unsanitized paths in taint flows are critical security risks that require immediate attention. The clean vulnerability history is a positive sign, but it does not negate the immediate threats presented by the identified entry points and taint issues.
Key Concerns
- Unprotected REST API route
- Taint flows with unsanitized paths
- No capability checks on entry points
Tilopay Security Vulnerabilities
Tilopay Release Timeline
Tilopay Code Analysis
Output Escaping
Data Flow Analysis
Tilopay Attack Surface
REST API Routes 1
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
Tilopay Maintenance & Trust
Maintenance Signals
Community Trust
Tilopay Alternatives
Dime Pay – Seamless Payment Processing for Your Business
dime-for-woocommerce
A custom payment gateway for WooCommerce that securely processes payments through our platform.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pay for Payment for WooCommerce
woocommerce-pay-for-payment
Setup individual charges for each payment method in WooCommerce.
Bold pagos en linea
bold-pagos-en-linea
Recibe pagos en tu tienda de forma segura con diferentes métodos de pago confiables.
Pay in Store WooCommerce Payment Gateway
pay-in-store-woocommerce-payment-gateway
Provides a Pay in Store upon pick up Payment Gateway for Woocommerce.
Tilopay Developer Profile
1 plugin · 1K total installs
How We Detect Tilopay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tilopay/assets/css/tilopay-checkout.css/wp-content/plugins/tilopay/assets/js/tilopay-checkout.js/wp-content/plugins/tilopay/assets/js/tilopay-admin.js/wp-content/plugins/tilopay/assets/js/tilopay-checkout.js/wp-content/plugins/tilopay/assets/js/tilopay-admin.jstilopay/assets/css/tilopay-checkout.css?ver=tilopay/assets/js/tilopay-checkout.js?ver=tilopay/assets/js/tilopay-admin.js?ver=HTML / DOM Fingerprints
tilopay-error-messagetilopay-success-messagetilopay-payment-gatewaytilopay_checkout_field<!-- add the action --><!-- For FE call form validation --><!-- Hook front script --><!-- Admin script to upload logo, only load at WC wc-settings page -->+4 moredata-tilopay-order-iddata-tilopay-amountdata-tilopay-currencytilopay_script_params/wp-json/tilopay/v1/validate-form