
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Security & Risk Analysis
wordpress.org/plugins/wallet-system-for-woocommerceThis plugin adds a digital wallet and Buy Now Pay Later feature to your WooCommerce store, allowing customers to add funds, check balances, and make s …
Is Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Safe to Use in 2026?
Generally Safe
Score 95/100Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments has a strong security track record. Known vulnerabilities have been patched promptly.
The "wallet-system-for-woocommerce" plugin v2.7.4 exhibits a mixed security posture, with several concerning aspects despite some good practices. While the plugin demonstrates a high percentage of properly escaped outputs and utilizes prepared statements for most SQL queries, the significant number of AJAX handlers lacking authorization checks (15 out of 20) presents a substantial attack surface. The presence of dangerous functions like `exec` is a critical red flag, and the three high-severity unsanitized taint flows indicate potential vulnerabilities in how user input is handled, which could lead to serious security issues. The plugin's history of 8 medium-severity CVEs, covering a range of common WordPress vulnerabilities like missing authorization, information exposure, CSRF, and XSS, suggests a recurring pattern of insecure coding practices. While there are no currently unpatched vulnerabilities, the historical trend and the static analysis findings point to a need for significant improvements in authorization and input sanitization to mitigate risks.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function 'exec' found
- High severity unsanitized taint flows
- History of 8 medium CVEs
- Bundled libraries (DataTables, dompdf, Select2) may be outdated
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Wallet System for WooCommerce <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation
Wallet System for WooCommerce <= 2.7.3 - Authenticated (Subscriber+) Information Exposure
Wallet System for WooCommerce <= 2.6.7 - Cross-Site Request Forgery
Wallet System for WooCommerce <= 2.6.8 - Reflected Cross-Site Scripting
Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery
Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization
Wallet System for WooCommerce <= 2.5.13 - Information Exposure via Log Files
Wallet System for WooCommerce <= 2.5.9 - Cross-Site Request Forgery
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Attack Surface
AJAX Handlers 20
Shortcodes 6
WordPress Hooks 147
Scheduled Events 5
Maintenance & Trust
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Maintenance & Trust
Maintenance Signals
Community Trust
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Alternatives
Wallet for WooCommerce
woo-wallet
A extendable WooCommerce wallet system which support payment, partial payment, cashback reward program as well as refund for your WooCommerce store.
Wallet & Cashback Plugin for WooCommerce
advanced-wallet-for-woocommerce
WooCommerce Wallet & Cashback Plugin is a powerful plugin that allows you to create a wallet system for your WooCommerce store.
FLIZpay Gateway für WooCommerce
flizpay-for-woocommerce
Mit dem FLIZpay-Plugin kannst du die Zahlungsmethode FLIZ in deinen Checkout integrieren. FLIZ ist für Shops und Zahlende gebührenfrei.
MemberPress Square — Accept Square Payments in MemberPress
pay-with-square-in-memberpress
Want to integrate Square payments in Memberpress for your wordpress site? Install Memberpress Square to accept Square Payments & create subscriptions.
Loya Pay
loya-pay
Give your customers 5% instant cashback and 1% referral rewards with Loya Pay.
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments Developer Profile
13 plugins · 43K total installs
How We Detect Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wallet-system-for-woocommerce/assets/css/backend.css/wp-content/plugins/wallet-system-for-woocommerce/assets/css/frontend.css/wp-content/plugins/wallet-system-for-woocommerce/assets/js/backend.js/wp-content/plugins/wallet-system-for-woocommerce/assets/js/frontend.js/wp-content/plugins/wallet-system-for-woocommerce/assets/js/backend.js/wp-content/plugins/wallet-system-for-woocommerce/assets/js/frontend.jswallet-system-for-woocommerce/assets/css/backend.css?ver=wallet-system-for-woocommerce/assets/css/frontend.css?ver=wallet-system-for-woocommerce/assets/js/backend.js?ver=wallet-system-for-woocommerce/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wps-wallet-admin-sidebarwps-wallet-backend-wrapperwps-wsfw-admin-dashboardwps-wsfw-menuwps-wsfw-page-titlewps-wsfw-product-tablewps-wsfw-settings-sectionwps-wsfw-user-balance+1 more<!-- Start: Wallet System for WooCommerce --><!-- End: Wallet System for WooCommerce -->data-wps-wsfw-currency-symboldata-wps-wsfw-user-idwps_wsfw_backend_paramswps_wsfw_frontend_params/wp-json/wps-wsfw/v1/wallet[wps_wsfw_wallet_balance][wps_wsfw_my_wallet][wps_wsfw_transactions]