IMMAGIT PayU LATAM Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-payu-payment-gateway

Receive online payments made with credit cards, bank transfers, cash and more from seven (7) countries through the PayU LATAM service in your WooComme …

70 active installs v1.1.3.1 PHP 7.0+ WP 5.6+ Updated Oct 27, 2023
ecommercegatewaysimmagitpayuwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IMMAGIT PayU LATAM Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

IMMAGIT PayU LATAM Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "wc-payu-payment-gateway" plugin version 1.1.3.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, utilizing prepared statements for all queries. It also avoids dangerous functions and file operations, and has no recorded vulnerability history, suggesting a potentially stable codebase. However, significant concerns arise from the attack surface analysis, which reveals two unprotected AJAX handlers. This lack of authentication checks on entry points is a critical security flaw, as it allows any authenticated user to potentially trigger these handlers, leading to unintended actions or information disclosure. The taint analysis also indicates potential issues, with two flows having unsanitized paths, though no critical or high severity vulnerabilities were identified in this analysis. The absence of nonce checks and capability checks further exacerbates the risk associated with the unprotected AJAX endpoints. While the plugin has no known CVEs, the presence of unprotected entry points and unsanitized flows represents a substantial risk that needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flows with unsanitized paths
  • No nonce checks on AJAX handlers
  • No capability checks on entry points
  • Low output escaping percentage
Vulnerabilities
None known

IMMAGIT PayU LATAM Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IMMAGIT PayU LATAM Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
20 prepared
Unescaped Output
22
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared20 total queries

Output Escaping

51% escaped45 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<payu-admin> (includes\admin\payu-admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

IMMAGIT PayU LATAM Payment Gateway for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_imma_close_admin_noticesincludes\admin\payu-admin.php:20
authwp_ajax_imma_replicate_payu_transactionincludes\admin\payu-admin.php:21
WordPress Hooks 19
actionadd_meta_boxesincludes\admin\payu-admin.php:19
actionadd_meta_boxesincludes\admin\payu-admin.php:22
actionrestrict_manage_postsincludes\class-functions-gateway-imma.php:15
actionwoocommerce_order_list_table_restrict_manage_ordersincludes\class-functions-gateway-imma.php:16
filterpre_get_postsincludes\class-functions-gateway-imma.php:17
filterwoocommerce_shop_order_list_table_prepare_items_query_argsincludes\class-functions-gateway-imma.php:18
filterwoocommerce_thankyou_order_idincludes\class-wc-gateway-payu.php:65
actionwoocommerce_email_before_order_tableincludes\class-wc-gateway-payu.php:67
filterwoocommerce_payment_complete_order_statusincludes\class-wc-gateway-payu.php:68
actiondo_payu_check_responseincludes\class-wc-gateway-payu.php:69
filterwoocommerce_can_restore_order_stockincludes\class-wc-gateway-payu.php:70
actionbefore_woocommerce_initwc-payu-payment-gateway.php:69
actionbefore_woocommerce_initwc-payu-payment-gateway.php:70
actionplugins_loadedwc-payu-payment-gateway.php:74
actionadmin_noticeswc-payu-payment-gateway.php:82
actionadmin_noticeswc-payu-payment-gateway.php:87
actionadmin_initwc-payu-payment-gateway.php:117
filterwoocommerce_payment_gatewayswc-payu-payment-gateway.php:128
actionadmin_noticeswc-payu-payment-gateway.php:155
Maintenance & Trust

IMMAGIT PayU LATAM Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 27, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

IMMAGIT PayU LATAM Payment Gateway for WooCommerce Developer Profile

IMMAGIT

2 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IMMAGIT PayU LATAM Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-payu-payment-gateway/assets/images/woomellyads1.gif

HTML / DOM Fingerprints

CSS Classes
immawmadsnotice-dismiss
JS Globals
ajaxurlimma_close_admin_noticesimma_replicate_payu_transaction
FAQ

Frequently Asked Questions about IMMAGIT PayU LATAM Payment Gateway for WooCommerce