
TopUp Security & Risk Analysis
wordpress.org/plugins/topup-africa-widgetEasy recharge for everyone! - TopUp Africa.
Is TopUp Safe to Use in 2026?
Generally Safe
Score 85/100TopUp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "topup-africa-widget" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and a remarkably small attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events identified. Furthermore, all SQL queries are properly prepared, mitigating the risk of SQL injection. However, significant concerns arise from the code signals. A concerning 0% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities when data is displayed to users. The presence of two taint flows with unsanitized paths, even without critical or high severity identified, suggests potential avenues for data manipulation or unexpected behavior if user-supplied data is not handled carefully. The absence of nonce checks and capability checks on any potential entry points, although the attack surface is currently zero, leaves the plugin exposed if new entry points are added without proper security measures. The file operations and external HTTP requests, while not inherently insecure without further context, warrant attention given the lack of other robust security checks.
Key Concerns
- Output escaping is 0% proper
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
TopUp Security Vulnerabilities
TopUp Release Timeline
TopUp Code Analysis
Output Escaping
Data Flow Analysis
TopUp Attack Surface
WordPress Hooks 2
Maintenance & Trust
TopUp Maintenance & Trust
Maintenance Signals
Community Trust
TopUp Alternatives
Subscriptions for WooCommerce
subscriptions-for-woocommerce
With WooCommerce Subscription, turn your physical or online store into a WooCommerce product subscription store and avail recurring revenue.
YITH WooCommerce Subscription
yith-woocommerce-subscription
It allows you to manage recurring payments for product subscription that grant you constant periodical income
WHMCS Bridge
whmcs-bridge
WHMCS Bridge is a plugin that integrates the powerful WHMCS support and billing software with WordPress.
Billingo Official for WooCommerce
billingo
Hivatalos Billingo összeköttetés WooCommerce-hez.
Remove Checkout Fields for Woocommerce
remove-default-checkout-fields-for-woocommerce
Remove Fields from woocommerce Checkout page
TopUp Developer Profile
1 plugin · 10 total installs
How We Detect TopUp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/topup-africa-widget/topupwidget.phpHTML / DOM Fingerprints
name="login"name="time"topup_getWidget