
IMMAGIT ePayco Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-epayco-payment-gatewayReceive payments by more than 22 means (credit card, digital wallet, bank transfer, cash and more payments) through the ePayco Colombia service in you …
Is IMMAGIT ePayco Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100IMMAGIT ePayco Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-epayco-payment-gateway" plugin, version 1.1.8, presents a concerning security posture due to a significant number of unprotected entry points. While the plugin exhibits good practices in its handling of SQL queries and avoids dangerous functions or file operations, the presence of two AJAX handlers without authentication checks is a major vulnerability. This allows any authenticated user, or potentially even unauthenticated users depending on the specific AJAX handler implementation, to trigger potentially harmful actions. The taint analysis, though limited in scope, did identify two flows with unsanitized paths, which, when combined with the unprotected entry points, indicates a risk of input manipulation that could lead to unintended behavior. The absence of any recorded vulnerability history is positive, suggesting a lack of past security flaws. However, this does not negate the immediate risks identified in the static analysis. The plugin has strengths in its database query practices and avoidance of common risky code patterns, but the critical lack of authorization on its AJAX endpoints is a significant weakness that requires immediate attention.
Key Concerns
- 2 unprotected AJAX handlers
- 2 flows with unsanitized paths
- 0 Nonce checks
- 0 Capability checks
- 57% properly escaped outputs
IMMAGIT ePayco Payment Gateway for WooCommerce Security Vulnerabilities
IMMAGIT ePayco Payment Gateway for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IMMAGIT ePayco Payment Gateway for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 20
Maintenance & Trust
IMMAGIT ePayco Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
IMMAGIT ePayco Payment Gateway for WooCommerce Alternatives
ePayco plugin for WooCommerce
epayco-gateway
The official ePayco plugin for WooCommerce allows seamless payment processing for your online store.
Beep Conditional Payments for WooCommerce
beep-conditional-payments
Control WooCommerce payment methods with flexible rules. Enable, disable, or add fees based on order, products, or customers.
Shetab Card Field For WooCommerce
woo-iran-shetab-card-field
Adding a field for receiving Shetab card number for WooCommerce
Amazon Pay for WooCommerce
woocommerce-gateway-amazon-payments-advanced
Install the Amazon Pay plugin for your WooCommerce store and take advantage of a seamless checkout experience
myPOS Checkout
mypos-virtual-for-woocommerce
One-click checkout with instant settlement. Accept all major cards, Apple Pay and Google Pay. No setup costs or monthly fees.
IMMAGIT ePayco Payment Gateway for WooCommerce Developer Profile
2 plugins · 130 total installs
How We Detect IMMAGIT ePayco Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-epayco-payment-gateway/assets/css/epayco.css/wp-content/plugins/wc-epayco-payment-gateway/assets/js/epayco.js/wp-content/plugins/wc-epayco-payment-gateway/assets/js/epayco.jswc-epayco-payment-gateway/assets/css/epayco.css?ver=wc-epayco-payment-gateway/assets/js/epayco.js?ver=HTML / DOM Fingerprints
epayco-checkout-formepayco_methods<!-- IMMAGIT ePayco Payment Gateway for WooCommerce --><!-- BEGIN WCGW_ePayco --><!-- END WCGW_ePayco --><!-- END wc_gw_epayco_missing_wc_notice -->+4 moredata-epayco-amountdata-epayco-currencydata-epayco-orderdata-epayco-merchantiddata-epayco-publickeydata-epayco-secure+2 moreepayco_params/wp-json/epayco-payment-gateway/v1/process_payment