Wallet Up Checkout for WPForms Security & Risk Analysis

wordpress.org/plugins/walup

This plugin helps you load Wallet Up P2P payments methods directly into WPForms Templates. Wallet Up and WPForms plugins are REQUIRED to be activated.

10 active installs v1.0.5 PHP 5.1+ WP 4.8+ Updated Unknown
cash-appvenmowallet-upwpformszelle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wallet Up Checkout for WPForms Safe to Use in 2026?

Generally Safe

Score 100/100

Wallet Up Checkout for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis and vulnerability history, the 'walup' v1.0.5 plugin exhibits a generally strong security posture concerning common attack vectors. The absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries and has no recorded vulnerabilities, indicating a lack of known exploits and a history of secure development. However, a critical concern arises from the complete lack of output escaping. This suggests that any data processed and displayed by the plugin is not being properly sanitized, leaving it vulnerable to cross-site scripting (XSS) attacks. The absence of nonce and capability checks, while not directly exposed by the current attack surface, represents a missed opportunity for robust authorization and could become a risk if functionality is added or exposed in the future. The lack of taint analysis flows is also noteworthy, suggesting either a very simple plugin or that the analysis may not have been comprehensive enough to detect potential data flow issues.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

Wallet Up Checkout for WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wallet Up Checkout for WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Wallet Up Checkout for WPForms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedincludes\class-walup.php:142
actionadmin_enqueue_scriptsincludes\class-walup.php:157
actionadmin_enqueue_scriptsincludes\class-walup.php:158
actionwp_enqueue_scriptsincludes\class-walup.php:173
actionwp_enqueue_scriptsincludes\class-walup.php:174
actioninittemplates\pages\walup_wpf_insert.php:74
actioninittemplates\pages\walup_wpf_insert.php:111
actionadmin_inittemplates\pages\walup_wpf_insert.php:168
actionwpforms_loadedtemplates\wpforms\walup-checkout-template.php:1379
actionwp_headwalup-code-snippets-json\walup-submit-condition.code-snippets.php:6
actionwpforms_wp_footer_endwalup-code-snippets-json\walup-submit-condition.code-snippets.php:45
actionadmin_noticeswalup.php:27
actionadmin_noticeswalup.php:32
Maintenance & Trust

Wallet Up Checkout for WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedUnknown
PHP min version5.1
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Wallet Up Checkout for WPForms Developer Profile

Wallet Up

3 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wallet Up Checkout for WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/walup/css/walup-admin.css/wp-content/plugins/walup/js/walup-admin.js
Script Paths
admin/js/walup-admin.js
Version Parameters
walup-admin.css?ver=walup-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
walup-containerwalup-wrapper
Data Attributes
data-walup-iddata-walup-action
JS Globals
WalupAdmin
REST Endpoints
/wp-json/walup/v1/checkout
Shortcode Output
[walup_checkout]
FAQ

Frequently Asked Questions about Wallet Up Checkout for WPForms