UniPayment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/unipayment-gateway-for-woocommerce

This plugin implements a payment gateway for WooCommerce to let buyers pay with Bitcoin, Ethereum, USDT, and other cryptocurrencies via UniPayment.io.

20 active installs v2.2.9 PHP + WP 4.9+ Updated Oct 23, 2024
bitcoinethereumunipaymentuscusdt
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is UniPayment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

UniPayment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of "unipayment-gateway-for-woocommerce" v2.2.9 reveals a strong adherence to several security best practices. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the complete avoidance of dangerous functions and the exclusive use of prepared statements for SQL queries are commendable. The plugin also exhibits no known vulnerability history, suggesting a generally secure development process.

However, the analysis does raise significant concerns regarding output escaping. With 100% of outputs not being properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin that is not sufficiently sanitized before rendering could be exploited by attackers. Additionally, the presence of file operations without further context and the bundling of Guzzle, a common HTTP client library, warrant closer inspection, though no specific threats are directly identified in the provided data. The complete lack of nonce and capability checks on any potential (though currently unidentified) entry points is also a weakness.

In conclusion, while the plugin's limited attack surface and secure handling of SQL are positive indicators, the widespread lack of output escaping is a critical flaw that requires immediate attention. The absence of known vulnerabilities is encouraging but does not negate the inherent risks posed by unescaped output. A thorough audit of output handling is highly recommended to mitigate potential XSS risks.

Key Concerns

  • Unescaped output
  • Bundled Guzzle library
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

UniPayment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

UniPayment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

0% escaped3 total outputs
Attack Surface

UniPayment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedindex.php:16
actionvalid-unipayment-requestindex.php:67
actionwoocommerce_update_options_payment_gatewaysindex.php:73
filterwoocommerce_payment_gatewaysindex.php:376
actionwoocommerce_blocks_loadedindex.php:379
actionwoocommerce_blocks_payment_method_type_registrationindex.php:383
Maintenance & Trust

UniPayment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 23, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

UniPayment Gateway for WooCommerce Developer Profile

unipayment

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UniPayment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unipayment-gateway-for-woocommerce/unipayment-gateway-for-woocommerce.php
Version Parameters
unipayment-gateway-for-woocommerce/unipayment-gateway-for-woocommerce.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about UniPayment Gateway for WooCommerce