
UddoktaPay Security & Risk Analysis
wordpress.org/plugins/uddoktapay-gatewayUddoktaPay Plugin for WooCommerce.
Is UddoktaPay Safe to Use in 2026?
Generally Safe
Score 100/100UddoktaPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "uddoktapay-gateway" plugin v2.6.3 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-point attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. File operations and external HTTP requests are present but do not appear to be a source of immediate concern without further context.
The taint analysis, however, reveals a potential area of concern with 4 flows identified with unsanitized paths. While no critical or high severity issues were flagged, this indicates that data might be flowing into sensitive functions without proper sanitization, which could be a vector for vulnerabilities if combined with other factors or specific input. The complete lack of known CVEs or historical vulnerabilities is a positive indicator, suggesting the developers are either highly diligent or the plugin has not been a target of past exploits. However, the presence of unsanitized paths, even without immediate exploitable consequences, warrants attention.
In conclusion, the plugin demonstrates good development practices regarding input validation, SQL security, and output escaping. The absence of historical vulnerabilities is a significant strength. The primary weakness identified is the presence of unsanitized paths in the taint analysis, which, while not currently leading to critical issues, represents a latent risk that should be investigated and remediated to further strengthen the plugin's security.
Key Concerns
- Unsanitized paths in taint flows
- Missing nonce checks
- Missing capability checks
UddoktaPay Security Vulnerabilities
UddoktaPay Release Timeline
UddoktaPay Code Analysis
Output Escaping
Data Flow Analysis
UddoktaPay Attack Surface
WordPress Hooks 13
Maintenance & Trust
UddoktaPay Maintenance & Trust
Maintenance Signals
Community Trust
UddoktaPay Alternatives
SoftTech-IT bKash, Rocket, Nagad
bkash
Easy to use bKash , Rocket and Nagad Payment Gateway for Woocommerce
Bangladeshi Payments Mobile – QR Code & Transaction Reports
bangladeshi-payments-mobile
Accept Mobile Payments in Bangladesh – WooCommerce Gateway for bKash, Nagad, Rocket & Upay with QR Code & Transaction Reports.
BanglaPress – bKash, & Mobile Payment with Order Tracking & Invoice & Shipping Label Printing for WooCommerce
bangla-press
bKash, Nagad, Rocket & Upay for WooCommerce — Label Print, Invoice, Order Tracker, Orders Manager.
CodeCareBD – Payment Gateway for WooCommerce
codecarebd-bkash-nagad-rocket-payoneer-gateway
CodeCareBD - Payment Gateway plugin integrates bKash, Nagad, Rocket, and Payoneer Payment Gateways with WooCommerce.
Flying Pay
flying-pay-gateway
A seamless and secure payment gateway integration for WooCommerce featuring Mobile Banking, 4 Major Banks, and Crypto support with an interactive UI.
UddoktaPay Developer Profile
1 plugin · 1K total installs
How We Detect UddoktaPay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/uddoktapay-gateway/assets/css/uddoktapay.css/wp-content/plugins/uddoktapay-gateway/assets/js/uddoktapay.js/wp-content/plugins/uddoktapay-gateway/assets/js/uddoktapay.jsuddoktapay-gateway/assets/css/uddoktapay.css?ver=uddoktapay-gateway/assets/js/uddoktapay.js?ver=HTML / DOM Fingerprints
uddoktapay-gateway-formdata-uddoktapay-gatewayuddoktapay_params/wp-json/uddoktapay/v1/gateway/process