
Payconiq Security & Risk Analysis
wordpress.org/plugins/wc-payconiqTo bring the ease of use of a Payconiq payment to the webshop, we developed a payment gateway integration for Payconiq in WooCommerce.
Is Payconiq Safe to Use in 2026?
Generally Safe
Score 92/100Payconiq has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wc-payconiq plugin version 1.0.4 presents a concerning security posture due to a significant number of unprotected AJAX endpoints. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and a reasonable rate of output escaping, the lack of authentication checks on its four identified AJAX handlers is a critical weakness. This means any user, including unauthenticated ones, could potentially trigger these handlers, leading to unauthorized actions or information disclosure.
The static analysis revealed no dangerous functions, SQL injection vulnerabilities, or file operation issues, which are positive indicators. Furthermore, the absence of any recorded vulnerabilities in its history suggests a generally stable codebase. However, the presence of unprotected AJAX handlers outweighs these strengths, creating a substantial attack surface. The single nonce check and capability check, while present, do not cover all the identified entry points, exacerbating the risk.
In conclusion, while wc-payconiq has a clean vulnerability history and good internal code practices like prepared statements, the unprotected AJAX endpoints are a significant security flaw. This warrants immediate attention to implement proper authentication and authorization checks to mitigate potential exploitation. The plugin's overall security posture is compromised by this specific oversight.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
- Output escaping not fully covered
Payconiq Security Vulnerabilities
Payconiq Code Analysis
Output Escaping
Payconiq Attack Surface
AJAX Handlers 4
WordPress Hooks 6
Maintenance & Trust
Payconiq Maintenance & Trust
Maintenance Signals
Community Trust
Payconiq Alternatives
WC Moneris Payment Gateway
wc-moneris-payment-gateway
A simple plugin that easily add moneris payment gateway to your WooCommerce website.
SkipCash Payment Gateway
skipcash-payment-gateway
SkipCash payment gateway for WooCommerce.
MANGOPAY for WooCommerce
mangopay-woocommerce
Official WooCommerce Payment gateway for the MANGOPAY payment solution dedicated to marketplaces.
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Payconiq Developer Profile
1 plugin · 200 total installs
How We Detect Payconiq
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-payconiq/assets/images/payconiq_mark.svgHTML / DOM Fingerprints
<!-- Logo and Name -->data-payconiq-mobile-linkpayconiq_payment_gateway_params/wp-json/payconiq/v1/payment