Tubapay Security & Risk Analysis

wordpress.org/plugins/tubapay-v2

Podzielenie płatności za zakupy Klientów oraz obsługa płatności abonamentowych / subskrypcji w WooCommerce. Wszyj w swoją ofertę pobieranie cyklicznyc …

100 active installs v3.1.4 PHP 7.0+ WP 6.0+ Updated Jan 8, 2026
paymentplatnoscirecurring-billingsubscription-billingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tubapay Safe to Use in 2026?

Generally Safe

Score 100/100

Tubapay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of the tubapay-v2 plugin v3.1.4 indicates a generally strong security posture, with no identified critical vulnerabilities in the analyzed code signals or taint flows. The absence of known CVEs and a lack of historical vulnerability data further suggest a well-maintained and secure plugin. The plugin demonstrates good practices by properly escaping a high percentage of its outputs and implementing capability checks. However, a few areas warrant attention. The use of raw SQL queries without prepared statements, while infrequent, presents a potential risk for SQL injection vulnerabilities. Additionally, the presence of file operations and external HTTP requests, even if seemingly benign in this analysis, always introduces a degree of risk that requires careful monitoring and validation. While the plugin's attack surface appears minimal, any future updates should continue to prioritize robust authentication and authorization checks for all entry points, and the practice of using prepared statements for all SQL queries should be adopted to mitigate potential risks.

Key Concerns

  • Raw SQL queries without prepared statements
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Tubapay Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tubapay Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
17
49 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

74% escaped66 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<functions> (functions\functions.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tubapay Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 45
filterquery_varsfunctions\api-handlers.php:4
actionparse_requestfunctions\api-handlers.php:10
actionadmin_noticesfunctions\functions.php:42
actionwoocommerce_blocks_payment_method_type_registrationfunctions\functions.php:268
actionwp_enqueue_scriptsfunctions\tooltip.php:12
actionwp_footerfunctions\tooltip.php:22
actionwp_body_openfunctions\tooltip.php:32
actionwp_enqueue_scriptsfunctions\top-bar.php:8
actionwp_footerfunctions\top-bar.php:21
actionwp_body_openfunctions\top-bar.php:34
filterwoocommerce_gateway_iconfunctions\tubapay-wc-gateway-class.php:43
actionwoocommerce_email_before_order_tablefunctions\tubapay-wc-gateway-class.php:73
actionwp_enqueue_scriptsfunctions\video-popup.php:5
actionwp_footerfunctions\video-popup.php:15
actionadmin_noticestubapay2.php:47
actionadmin_inittubapay2.php:53
actionplugins_loadedtubapay2.php:57
filterinittubapay2.php:65
filteruser_has_captubapay2.php:67
filtersafe_style_csstubapay2.php:75
actionadd_meta_boxestubapay2.php:82
actionparse_requesttubapay2.php:85
actionadmin_noticestubapay2.php:92
actionadmin_enqueue_scriptstubapay2.php:109
actionmanage_shop_order_posts_custom_columntubapay2.php:111
actionbefore_woocommerce_paytubapay2.php:113
actionbefore_woocommerce_inittubapay2.php:120
actionwoocommerce_blocks_loadedtubapay2.php:127
filterwoocommerce_payment_gatewaystubapay2.php:135
actionwoocommerce_admin_order_data_after_billing_addresstubapay2.php:143
filterwoocommerce_available_payment_gatewaystubapay2.php:152
filterwc_order_statusestubapay2.php:154
filterwoocommerce_order_is_paid_statusestubapay2.php:156
filterwoocommerce_valid_order_statuses_for_paymenttubapay2.php:158
filterwoocommerce_add_to_cart_validationtubapay2.php:160
actionwoocommerce_before_add_to_cart_formtubapay2.php:162
filterwoocommerce_gateway_descriptiontubapay2.php:164
actionwoocommerce_checkout_processtubapay2.php:166
actionwoocommerce_checkout_create_ordertubapay2.php:168
actionwoocommerce_get_order_item_totalstubapay2.php:170
actionwoocommerce_admin_order_data_after_order_detailstubapay2.php:172
actionwoocommerce_order_status_changedtubapay2.php:174
filtermanage_edit-shop_order_columnstubapay2.php:176
filtermanage_woocommerce_page_wc-orders_columnstubapay2.php:178
actionmanage_woocommerce_page_wc-orders_custom_columntubapay2.php:180
Maintenance & Trust

Tubapay Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Tubapay Developer Profile

tubapay

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tubapay

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tubapay-v2/assets/js/admin.js/wp-content/plugins/tubapay-v2/assets/css/tooltip.css/wp-content/plugins/tubapay-v2/assets/js/tooltip.js
Script Paths
/wp-content/plugins/tubapay-v2/assets/js/admin.js/wp-content/plugins/tubapay-v2/assets/js/tooltip.js
Version Parameters
tubapay-v2/assets/js/admin.js?ver=tubapay-v2/assets/css/tooltip.css?ver=tubapay-v2/assets/js/tooltip.js?ver=

HTML / DOM Fingerprints

CSS Classes
tubapay_tooltiptubapay-tooltip-container
Data Attributes
data-tubapay_tooltip_iddata-tubapay_tooltip_widthdata-tubapay_tooltip_colordata-tubapay_tooltip_text
JS Globals
TubaPaytubapay_gateway_datatubapay_configtubapay_options
REST Endpoints
/wp-json/tubapay/v1/settings/wp-json/tubapay/v1/payment
FAQ

Frequently Asked Questions about Tubapay