6amTech – Payment Gateway for bKash and WC Security & Risk Analysis

wordpress.org/plugins/wc-6amtech-payment-gateway-bkash

6amTech – Payment Gateway for bKash and WooCommerce allows seamless bKash integration, making transactions secure and easy for Bangladeshi customers.

200 active installs v1.2.2 PHP 7.4+ WP 5.1+ Updated Sep 9, 2025
bkashbkash-for-woocommercebkash-paymentbkash-payment-gatewaypayment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 6amTech – Payment Gateway for bKash and WC Safe to Use in 2026?

Generally Safe

Score 100/100

6amTech – Payment Gateway for bKash and WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of wc-6amtech-payment-gateway-bkash v1.2.2 indicates a generally strong security posture, with no dangerous functions, file operations, or SQL queries executed without prepared statements. The high percentage of properly escaped output (84%) is also a positive sign. However, the complete absence of nonce checks and capability checks across all entry points, combined with a lack of taint analysis data, presents a significant area of concern. While the plugin has no recorded vulnerability history, this can be misleading. The lack of detailed taint analysis means that potential vulnerabilities might not have been detected by the analysis tools, and the absence of security checks leaves it open to exploitation if vulnerabilities do exist.

Despite the clean vulnerability history and good coding practices in other areas, the lack of fundamental security controls like nonces and capability checks for all entry points is a serious weakness. This makes the plugin susceptible to various attacks, including Cross-Site Request Forgery (CSRF) and unauthorized actions if any vulnerabilities are introduced in the future. The external HTTP requests also warrant careful scrutiny to ensure they are not points of compromise. Overall, while the plugin demonstrates some good practices, the missing security checks introduce a notable risk that needs to be addressed.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • No taint analysis data available
  • External HTTP requests present
Vulnerabilities
None known

6amTech – Payment Gateway for bKash and WC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

6amTech – Payment Gateway for bKash and WC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

84% escaped57 total outputs
Attack Surface

6amTech – Payment Gateway for bKash and WC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionadmin_menuadmin\class-pgbw-menu-settings.php:30
filterwoocommerce_available_payment_gatewaysincludes\class-pgbw-init-webhooks.php:16
actionadmin_noticesincludes\class-pgbw-init-webhooks.php:17
filterwoocommerce_payment_gatewaysincludes\class-pgbw-init-webhooks.php:18
actionwoocommerce_product_options_pricingincludes\class-pgbw-init-webhooks.php:19
actionwoocommerce_process_product_metaincludes\class-pgbw-init-webhooks.php:20
filterwoocommerce_product_get_priceincludes\class-pgbw-init-webhooks.php:21
filterwoocommerce_product_get_regular_priceincludes\class-pgbw-init-webhooks.php:22
filterwoocommerce_product_get_sale_priceincludes\class-pgbw-init-webhooks.php:23
filterwoocommerce_currencyincludes\class-pgbw-init-webhooks.php:24
filterwoocommerce_currency_symbolincludes\class-pgbw-init-webhooks.php:25
actionwoocommerce_thankyouincludes\class-pgbw-init-webhooks.php:26
actionwp_footerincludes\class-pgbw-init-webhooks.php:27
actionwoocommerce_order_details_after_order_tableincludes\class-pgbw-init-webhooks.php:28
actionwoocommerce_cart_calculate_feesincludes\class-pgbw-payment.php:45
actionwoocommerce_thankyouincludes\class-pgbw-payment.php:46
actionplugins_loadedincludes\class-pgbw.php:60
actionadmin_enqueue_scriptsincludes\class-pgbw.php:90
actionadmin_enqueue_scriptsincludes\class-pgbw.php:91
actionadmin_noticeswc-6amtech-payment-gateway-bkash.php:39
actionplugins_loadedwc-6amtech-payment-gateway-bkash.php:55
Maintenance & Trust

6amTech – Payment Gateway for bKash and WC Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 9, 2025
PHP min version7.4
Downloads4K

Community Trust

Rating94/100
Number of ratings6
Active installs200
Developer Profile

6amTech – Payment Gateway for bKash and WC Developer Profile

6amtech

3 plugins · 210 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 6amTech – Payment Gateway for bKash and WC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-6amtech-payment-gateway-bkash/admin/css/pgbw-admin-common.css/wp-content/plugins/wc-6amtech-payment-gateway-bkash/admin/js/pgbw-payment-list.js/wp-content/plugins/wc-6amtech-payment-gateway-bkash/assets/bootstrap/js/bootstrap.bundle.js/wp-content/plugins/wc-6amtech-payment-gateway-bkash/assets/bootstrap/css/bootstrap.min.css
Script Paths
/wp-content/plugins/wc-6amtech-payment-gateway-bkash/admin/js/pgbw-payment-list.js
Version Parameters
wc-6amtech-payment-gateway-bkash/admin/css/pgbw-admin-common.css?ver=wc-6amtech-payment-gateway-bkash/admin/js/pgbw-payment-list.js?ver=

HTML / DOM Fingerprints

CSS Classes
pgbw-admin-common
FAQ

Frequently Asked Questions about 6amTech – Payment Gateway for bKash and WC