
6amTech – Payment Gateway for bKash and WC Security & Risk Analysis
wordpress.org/plugins/wc-6amtech-payment-gateway-bkash6amTech – Payment Gateway for bKash and WooCommerce allows seamless bKash integration, making transactions secure and easy for Bangladeshi customers.
Is 6amTech – Payment Gateway for bKash and WC Safe to Use in 2026?
Generally Safe
Score 100/1006amTech – Payment Gateway for bKash and WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wc-6amtech-payment-gateway-bkash v1.2.2 indicates a generally strong security posture, with no dangerous functions, file operations, or SQL queries executed without prepared statements. The high percentage of properly escaped output (84%) is also a positive sign. However, the complete absence of nonce checks and capability checks across all entry points, combined with a lack of taint analysis data, presents a significant area of concern. While the plugin has no recorded vulnerability history, this can be misleading. The lack of detailed taint analysis means that potential vulnerabilities might not have been detected by the analysis tools, and the absence of security checks leaves it open to exploitation if vulnerabilities do exist.
Despite the clean vulnerability history and good coding practices in other areas, the lack of fundamental security controls like nonces and capability checks for all entry points is a serious weakness. This makes the plugin susceptible to various attacks, including Cross-Site Request Forgery (CSRF) and unauthorized actions if any vulnerabilities are introduced in the future. The external HTTP requests also warrant careful scrutiny to ensure they are not points of compromise. Overall, while the plugin demonstrates some good practices, the missing security checks introduce a notable risk that needs to be addressed.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- No taint analysis data available
- External HTTP requests present
6amTech – Payment Gateway for bKash and WC Security Vulnerabilities
6amTech – Payment Gateway for bKash and WC Code Analysis
Output Escaping
6amTech – Payment Gateway for bKash and WC Attack Surface
WordPress Hooks 21
Maintenance & Trust
6amTech – Payment Gateway for bKash and WC Maintenance & Trust
Maintenance Signals
Community Trust
6amTech – Payment Gateway for bKash and WC Alternatives
Bangladeshi Payment Gateways – Make Payment Using QR Code
bangladeshi-payment-gateways
Bangladeshi Payment Gateways for WooCommerce.
CodeCareBD – Payment Gateway for WooCommerce
codecarebd-bkash-nagad-rocket-payoneer-gateway
CodeCareBD - Payment Gateway plugin integrates bKash, Nagad, Rocket, and Payoneer Payment Gateways with WooCommerce.
Flying Pay
flying-pay-gateway
A seamless and secure payment gateway integration for WooCommerce featuring Mobile Banking, 4 Major Banks, and Crypto support with an interactive UI.
DC EDD bKash Payment
dc-edd-bkash-payment
bKash payment gateway for Easy Digital Downloads.
Deshi Pay bKash, Rocket, Nagad
deshi-pay
A professional and modern manual payment gateway for WooCommerce supporting bKash, Nagad, and Rocket with a sleek UI and easy copy features.
6amTech – Payment Gateway for bKash and WC Developer Profile
3 plugins · 210 total installs
How We Detect 6amTech – Payment Gateway for bKash and WC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-6amtech-payment-gateway-bkash/admin/css/pgbw-admin-common.css/wp-content/plugins/wc-6amtech-payment-gateway-bkash/admin/js/pgbw-payment-list.js/wp-content/plugins/wc-6amtech-payment-gateway-bkash/assets/bootstrap/js/bootstrap.bundle.js/wp-content/plugins/wc-6amtech-payment-gateway-bkash/assets/bootstrap/css/bootstrap.min.css/wp-content/plugins/wc-6amtech-payment-gateway-bkash/admin/js/pgbw-payment-list.jswc-6amtech-payment-gateway-bkash/admin/css/pgbw-admin-common.css?ver=wc-6amtech-payment-gateway-bkash/admin/js/pgbw-payment-list.js?ver=HTML / DOM Fingerprints
pgbw-admin-common