
UnitechPay – Wave & Orange Money Payments Security & Risk Analysis
wordpress.org/plugins/unitechpay-paiements-mobile-moneySolution complète de paiement Wave et Orange Money avec redistribution automatique. Recevez directement l'argent sur vos numéros !
Is UnitechPay – Wave & Orange Money Payments Safe to Use in 2026?
Generally Safe
Score 100/100UnitechPay – Wave & Orange Money Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The UnitechPay Payments Mobile Money plugin version 1.0.2 demonstrates a generally good security posture with several positive indicators. The absence of known vulnerabilities and the use of prepared statements for all SQL queries are significant strengths. The plugin also implements nonce checks for its entry points, which is a crucial security measure for WordPress plugins. Furthermore, the static analysis reveals no critical or high-severity taint flows, suggesting that data processing within the plugin is likely handled with reasonable care regarding sanitization. The limited attack surface with no unprotected entry points is also commendable.
However, there are areas that warrant attention. A notable concern is the presence of one flow with unsanitized paths identified in the taint analysis. While not classified as critical or high, this could potentially lead to path traversal or file manipulation vulnerabilities if an attacker can control the path. Additionally, the plugin exhibits a moderate percentage of unescaped output (25% of 102 outputs), which could leave the door open for cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The zero capability checks found also means that access to certain functionalities might not be properly restricted based on user roles.
In conclusion, UnitechPay Payments Mobile Money v1.0.2 is a plugin with a solid foundation in security best practices, particularly concerning its lack of known vulnerabilities and secure database interactions. Nevertheless, the identified unsanitized path flow and the proportion of unescaped output represent potential risks that should be addressed to further harden its security. The absence of capability checks for its entry points is also a weakness that could be exploited in certain scenarios.
Key Concerns
- Flows with unsanitized paths identified
- Unescaped output detected
- No capability checks on entry points
UnitechPay – Wave & Orange Money Payments Security Vulnerabilities
UnitechPay – Wave & Orange Money Payments Code Analysis
Output Escaping
Data Flow Analysis
UnitechPay – Wave & Orange Money Payments Attack Surface
AJAX Handlers 2
WordPress Hooks 23
Maintenance & Trust
UnitechPay – Wave & Orange Money Payments Maintenance & Trust
Maintenance Signals
Community Trust
UnitechPay – Wave & Orange Money Payments Alternatives
Paiement Wave Senegal
paiement-wave-senegal
Une extension WooCommerce pour accepter les paiements via Wave Mobile Money au Sénégal.
Campay Woocommerce Payment Gateway
campay-api
CamPay is a Fintech service of the company TAKWID
SmobilPay for e-commerce – Mobile Money Gateway for WooCommerce
e-nkap-woocommerce-gateway
A secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or website
Akouendy Mobile Money Gateway for WooCommerce
akouendy-woocommerce-orange-money-gateway
The plugins is Senegal Mobile Money gateway for Woocommerce.
SmobilPay for e-commerce Gateway for Easy Digital Downloads
smobilplay-edd-gateway
SmobilPay Easy Digital Downloads is a secure and seamless plugin to receive and manage Cash, Mobile, and Card payments in Cameroon on your e-shop or w …
UnitechPay – Wave & Orange Money Payments Developer Profile
2 plugins · 200 total installs
How We Detect UnitechPay – Wave & Orange Money Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unitechpay-paiements-mobile-money/assets/css/unitechpay.css/wp-content/plugins/unitechpay-paiements-mobile-money/assets/css/fontawesome.min.css/wp-content/plugins/unitechpay-paiements-mobile-money/assets/js/unitechpay.js/wp-content/plugins/unitechpay-paiements-mobile-money/assets/js/unitechpay.jsunitechpay-paiements-mobile-money/assets/css/unitechpay.css?ver=unitechpay-paiements-mobile-money/assets/css/fontawesome.min.css?ver=unitechpay-paiements-mobile-money/assets/js/unitechpay.js?ver=HTML / DOM Fingerprints
unitechpay_gatewayunitechpay_ajax