
Wallet Up Security & Risk Analysis
wordpress.org/plugins/wallet-upAccept payments via Cash App, Venmo, Zelle & PayPal with QR codes. Perfect for WooCommerce checkout & donation pages.
Is Wallet Up Safe to Use in 2026?
Generally Safe
Score 100/100Wallet Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wallet-up' v4.2.0 plugin exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no recorded CVEs, indicating good development practices or a lack of past significant issues. The static analysis also shows a strong adherence to prepared statements for SQL queries (74%), good output escaping (82%), and a reasonable number of nonce and capability checks. However, there are notable security concerns.
The plugin has a significant attack surface with 43 AJAX handlers, and alarmingly, 13 of these lack authentication checks. This presents a considerable risk of unauthorized access or malicious function calls. Furthermore, the taint analysis reveals 7 flows with unsanitized paths, including 6 of high severity. This suggests that user-supplied data might be processed in a way that could lead to vulnerabilities like path traversal or arbitrary file read/write if exploited.
In conclusion, while the plugin benefits from a clean CVE history and good practices in areas like SQL and output escaping, the high number of unprotected AJAX endpoints and critical taint flows represent substantial risks that require immediate attention. The absence of known vulnerabilities doesn't negate the inherent dangers exposed by the static and taint analysis.
Key Concerns
- AJAX handlers without auth checks
- High severity unsanitized taint flows
- Unsanitized paths in taint analysis
- Bundled Freemius v1.0 library
Wallet Up Security Vulnerabilities
Wallet Up Release Timeline
Wallet Up Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Wallet Up Attack Surface
AJAX Handlers 43
Shortcodes 2
WordPress Hooks 134
Scheduled Events 1
Maintenance & Trust
Wallet Up Maintenance & Trust
Maintenance Signals
Community Trust
Wallet Up Alternatives
Receive customer payments on Woocommerce
momo-venmo
Receive Venmo payments on your website with WooCommerce + Venmo
Checkout with Cash App on WooCommerce
wc-cashapp
The #1 finance app in the App Store now available on WordPress. Receive Cash App payments on your website with WooCommerce + Cash App
Checkout Gateway for IRIS
checkout-gateway-iris
Unofficial IRIS checkout payment gateway for WooCommerce. Accept payments via IRIS and manage order statuses efficiently.
Knit Pay UPI – Paytm for Business, PhonePe Business, BharatPe, HDFC
knit-pay-upi
Knit Pay UPI simplifies UPI QR code integration for your website and updates the payment status as soon as your customer completes the transaction.
FM: QR Code Gateway for WooCommerce
fm-qr-code-gateway
Accept UPI payments via QR code in WooCommerce. Customers enter Transaction ID at checkout. Lightweight & easy to configure.
Wallet Up Developer Profile
3 plugins · 110 total installs
How We Detect Wallet Up
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wallet-up/assets/css/wallet-up.css/wp-content/plugins/wallet-up/assets/js/wallet-up.js/wp-content/plugins/wallet-up/assets/js/backend/admin-script.js/wp-content/plugins/wallet-up/assets/js/frontend/qr-generator.js/wp-content/plugins/wallet-up/assets/js/frontend/wallet-up-script.js/wp-content/plugins/wallet-up/assets/js/wallet-up.js/wp-content/plugins/wallet-up/assets/js/backend/admin-script.js/wp-content/plugins/wallet-up/assets/js/frontend/qr-generator.js/wp-content/plugins/wallet-up/assets/js/frontend/wallet-up-script.jswallet-up/assets/css/wallet-up.css?ver=wallet-up/assets/js/wallet-up.js?ver=wallet-up/assets/js/backend/admin-script.js?ver=wallet-up/assets/js/frontend/qr-generator.js?ver=wallet-up/assets/js/frontend/wallet-up-script.js?ver=HTML / DOM Fingerprints
wallet-up-qr-code-containerdata-wallet-up-currencydata-wallet-up-amountdata-wallet-up-methoddata-wallet-up-recipientdata-wallet-up-notedata-wallet-up-qr-code-size+2 morewalletUpAdmin/wp-json/wallet-up/v1/generate-qr[wallet-up-qr-code]