WaafiPay Payment Gateway Security & Risk Analysis

wordpress.org/plugins/waafipay-payment-gateway-for-woocommerce

WaafiPay Plugin for WooCommerce, officially created by Safarifone Inc, allows your customer to Pay through Mobile Money Wallets, VISA and Mastercard.

100 active installs v1.1.0 PHP 5.4+ WP 5.4+ Updated Feb 2, 2022
paymentgatewayvisawaafipaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WaafiPay Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

WaafiPay Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of waafipay-payment-gateway-for-woocommerce v1.1.0 reveals a generally strong security posture, with no critical or high-severity findings in code signals or taint analysis. The plugin demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output. The absence of file operations and dangerous functions further contributes to its secure design. However, the lack of nonce checks and capability checks on any entry points, despite there being none identified in this specific analysis, is a significant concern. The presence of external HTTP requests without specified authentication or sanitization mechanisms also warrants attention.

The vulnerability history is notably clean, with no recorded CVEs. This indicates either a history of secure development or a lack of significant past vulnerabilities being publicly disclosed. While this is a positive sign, it does not negate the potential risks identified in the static analysis, particularly concerning the missing security checks on potential future entry points and the handling of external HTTP requests. The plugin's strengths lie in its secure data handling for SQL and output, but its weaknesses lie in the potential for future vulnerabilities due to missing fundamental security checks.

Key Concerns

  • No Nonce Checks on Entry Points
  • No Capability Checks on Entry Points
  • External HTTP Requests without Details
Vulnerabilities
None known

WaafiPay Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WaafiPay Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped17 total outputs
Attack Surface

WaafiPay Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_api_waafisuccessincludes\abstracts\abstract-wc-gateway-waafi.php:48
actionwoocommerce_api_waafifailincludes\abstracts\abstract-wc-gateway-waafi.php:49
actionwp_footerincludes\abstracts\abstract-wc-gateway-waafi.php:50
filterwoocommerce_payment_gatewaysincludes\class-wc-gateway-waafi-gateway-loader.php:20
actionplugins_loadedincludes\class-wc-gateway-waafi-plugin.php:33
actionadmin_noticesincludes\class-wc-gateway-waafi-plugin.php:52
Maintenance & Trust

WaafiPay Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedFeb 2, 2022
PHP min version5.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

WaafiPay Payment Gateway Developer Profile

WaafiPay Payment Gateway

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WaafiPay Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/waafipay-payment-gateway-for-woocommerce/assets/js/custom.js
Script Paths
../assets/js/custom.js

HTML / DOM Fingerprints

REST Endpoints
/wp-json/waafisuccess/wp-json/waafifail
FAQ

Frequently Asked Questions about WaafiPay Payment Gateway