UnitechPay – Wave & Orange Money Payments Security & Risk Analysis

wordpress.org/plugins/unitechpay-paiements-mobile-money

Solution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !

100 active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Mar 10, 2026
mobile-moneyorange-moneysenegalwavewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is UnitechPay – Wave & Orange Money Payments Safe to Use in 2026?

Generally Safe

Score 100/100

UnitechPay – Wave & Orange Money Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

The UnitechPay Payments Mobile Money plugin version 1.0.2 demonstrates a generally good security posture with several positive indicators. The absence of known vulnerabilities and the use of prepared statements for all SQL queries are significant strengths. The plugin also implements nonce checks for its entry points, which is a crucial security measure for WordPress plugins. Furthermore, the static analysis reveals no critical or high-severity taint flows, suggesting that data processing within the plugin is likely handled with reasonable care regarding sanitization. The limited attack surface with no unprotected entry points is also commendable.

However, there are areas that warrant attention. A notable concern is the presence of one flow with unsanitized paths identified in the taint analysis. While not classified as critical or high, this could potentially lead to path traversal or file manipulation vulnerabilities if an attacker can control the path. Additionally, the plugin exhibits a moderate percentage of unescaped output (25% of 102 outputs), which could leave the door open for cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The zero capability checks found also means that access to certain functionalities might not be properly restricted based on user roles.

In conclusion, UnitechPay Payments Mobile Money v1.0.2 is a plugin with a solid foundation in security best practices, particularly concerning its lack of known vulnerabilities and secure database interactions. Nevertheless, the identified unsanitized path flow and the proportion of unescaped output represent potential risks that should be addressed to further harden its security. The absence of capability checks for its entry points is also a weakness that could be exploited in certain scenarios.

Key Concerns

  • Flows with unsanitized paths identified
  • Unescaped output detected
  • No capability checks on entry points
Vulnerabilities
None known

UnitechPay – Wave & Orange Money Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

UnitechPay – Wave & Orange Money Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
77 escaped
Nonce Checks
2
Capability Checks
0
File Operations
3
External Requests
5
Bundled Libraries
0

Output Escaping

75% escaped102 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
unitechpay_bulk_action_notices (unitechpay.php:1595)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

UnitechPay – Wave & Orange Money Payments Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_unitechpay_check_payment_statusunitechpay.php:191
noprivwp_ajax_unitechpay_check_payment_statusunitechpay.php:192
WordPress Hooks 23
actionplugins_loadedunitechpay.php:25
actionadmin_noticesunitechpay.php:28
actionadmin_initunitechpay.php:38
actionadmin_initunitechpay.php:74
actionadmin_noticesunitechpay.php:88
filterwoocommerce_available_payment_gatewaysunitechpay.php:117
filterwoocommerce_payment_gatewaysunitechpay.php:129
actionwp_enqueue_scriptsunitechpay.php:138
actioninitunitechpay.php:153
actionparse_requestunitechpay.php:154
actionplugins_loadedunitechpay.php:783
actionwp_footerunitechpay.php:1278
actionwoocommerce_admin_order_data_after_billing_addressunitechpay.php:1452
actionwoocommerce_checkout_processunitechpay.php:1485
actioninitunitechpay.php:1518
filterwc_order_statusesunitechpay.php:1530
filtermanage_edit-shop_order_columnsunitechpay.php:1536
actionmanage_shop_order_posts_custom_columnunitechpay.php:1542
filterbulk_actions-edit-shop_orderunitechpay.php:1566
filterhandle_bulk_actions-edit-shop_orderunitechpay.php:1572
actionadmin_noticesunitechpay.php:1594
filterplugin_row_metaunitechpay.php:1619
filterplugin_row_metaunitechpay.php:1630
Maintenance & Trust

UnitechPay – Wave & Orange Money Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

UnitechPay – Wave & Orange Money Payments Developer Profile

Unitech Web

2 plugins · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UnitechPay – Wave & Orange Money Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unitechpay-paiements-mobile-money/assets/css/unitechpay.css/wp-content/plugins/unitechpay-paiements-mobile-money/assets/css/fontawesome.min.css/wp-content/plugins/unitechpay-paiements-mobile-money/assets/js/unitechpay.js
Script Paths
/wp-content/plugins/unitechpay-paiements-mobile-money/assets/js/unitechpay.js
Version Parameters
unitechpay-paiements-mobile-money/assets/css/unitechpay.css?ver=unitechpay-paiements-mobile-money/assets/css/fontawesome.min.css?ver=unitechpay-paiements-mobile-money/assets/js/unitechpay.js?ver=

HTML / DOM Fingerprints

Data Attributes
unitechpay_gateway
JS Globals
unitechpay_ajax
FAQ

Frequently Asked Questions about UnitechPay – Wave & Orange Money Payments