[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffZCfdQ73rIqu9GXX20PweGjCME2AN3JJLwJtUd4buQ4":3,"$fgl0idvl3dMJRkS0jGwvGMh36lXNHKSNdPWmpSfZEOgQ":286,"$feKUD_33vmxYtHKU93RU7u-fiknP8WRSFkvQibTRsvNY":290},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":31,"crawl_stats":27,"alternatives":36,"analysis":130,"fingerprints":259},"wc-vpay","VPay Payment Gateway for WooCommerce","1.1.0","vpayafrica","https:\u002F\u002Fprofiles.wordpress.org\u002Fvpayafrica\u002F","\u003Cp>This is VPay payment gateway for WooCommerce.\u003C\u002Fp>\n\u003Cp>VPay is a payment solution that enables cashiers and online shopping carts to increase customer loyalty by accepting payments via bank transfer and instantly confirm these payments without depending on the business owner or accountant.\u003C\u002Fp>\n\u003Cp>VPay is a payment gateway for businesses to accept payments from customers, either on a recurring or one-time basis. VPay offers an easier, faster and cheaper way for businesses to get paid on their web and mobile applications using convenient payment methods for customers with the highest success rates obtainable.\u003C\u002Fp>\n\u003Cp>With VPay Payment Gateway for WooCommerce, you can accept payments via:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Credit\u002FDebit Cards — Visa, Mastercard, Verve (NG)\u003C\u002Fli>\n\u003Cli>Bank transfer (Nigeria)\u003C\u002Fli>\n\u003Cli>USSD (Nigeria)\u003C\u002Fli>\n\u003Cli>Many more coming soon\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why VPay?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easy Reconciliation. VPay makes it simple for you to balance your books because we handle all the difficult tasks in real time, letting you know who paid for what and when it was paid.\u003C\u002Fli>\n\u003Cli>Start receiving payments instantly—go from sign-up to your first real transaction in as little as 10 minutes\u003C\u002Fli>\n\u003Cli>Simple, transparent pricing—no hidden charges or fees.\u003C\u002Fli>\n\u003Cli>Intelligent fraud detection\u003C\u002Fli>\n\u003Cli>Fully Featured Sandbox\u003C\u002Fli>\n\u003Cli>Understand your customers better through a simple and elegant dashboard\u003C\u002Fli>\n\u003Cli>Access to attentive, empathetic customer support 24\u002F7\u003C\u002Fli>\n\u003Cli>Free updates as we launch new features and payment options\u003C\u002Fli>\n\u003Cli>Clearly documented APIs to build your custom payment experiences\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Over 50,000 businesses of all sizes in Nigeria rely on VPay’s suite of products to receive payments and make payouts seamlessly. Sign up on \u003Ca href=\"https:\u002F\u002Fvpay.africa\u002Fsignup\" rel=\"nofollow ugc\">vpay.africa\u002Fsignup\u003C\u002Fa> to get started.\u003C\u002Fp>\n\u003Ch4>Note\u003C\u002Fh4>\n\u003Cp>This plugin is meant to be used by merchants in Nigeria.\u003C\u002Fp>\n\u003Ch4>Plugin Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Accept payment\u003C\u002Fstrong> via Mastercard, Visa, Verve, USSD, Bank Transfer.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless integration\u003C\u002Fstrong> into the WooCommerce checkout page. Accept payment directly on your site\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Suggestions \u002F Feature Request\u003C\u002Fh4>\n\u003Cp>If you have suggestions or a new feature request, feel free to get in touch with me via the contact form on my website \u003Ca href=\"https:\u002F\u002Fvpay.africa\u002Fcontact\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>You can also follow me on Twitter! \u003Cstrong>\u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Fmyvpayafrica\" rel=\"nofollow ugc\">@myvpayafrica\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n","VPay Payment Gateway for WooCommerce enables you receive instant and fast payments via bank transfer, USSD and card payment.",20,1962,0,"2024-02-09T12:45:00.000Z","6.4.8","4.7","7.0",[19,20,21,22,23],"dare-kolawole-plugins","payment-gateway","verve","vpay","woocommerce","https:\u002F\u002Fdocs.vpay.africa\u002Fwoocommerce-plugin-specification\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwc-vpay.1.2.zip",85,null,"2026-07-22T17:31:50.256Z","no_bundle",[],{"slug":7,"display_name":7,"profile_url":8,"plugin_count":32,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":33,"trust_score":34,"computed_at":35},1,30,84,"2026-08-29T19:24:54.406Z",[37,56,77,94,109],{"slug":38,"name":39,"version":40,"author":41,"author_profile":42,"description":43,"short_description":44,"active_installs":45,"downloaded":46,"rating":11,"num_ratings":32,"last_updated":47,"tested_up_to":48,"requires_at_least":16,"requires_php":49,"tags":50,"homepage":53,"download_link":54,"security_score":55,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"monnify-payment-gateway","Payment Gateway for Monnify on WooCommerce","1.0.10","Adeleye Ayodeji","https:\u002F\u002Fprofiles.wordpress.org\u002Fbiodunhi\u002F","\u003Cp>This is a Monnify payment gateway for WooCommerce.\u003C\u002Fp>\n\u003Cp>Monnify is on a mission to deliver a safe and convenient payment experience for customers and merchants. Monnify provide Nigerian & Ghanaian merchants with the tools and services needed to accept online payments from local and international customers using Mastercard, Visa, Verve, Bank Accounts\u003C\u002Fp>\n\u003Cp>To signup for a Monnify Merchant account visit their website by clicking \u003Ca href=\"https:\u002F\u002Fmonnify.com\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Payment Gateway for Monnify on WooCommerce allows you to accept payment on your WooCommerce store using Mastercard, Visa, Verve, bank accounts\u003C\u002Fp>\n\u003Cp>With this Payment Gateway for Monnify on WooCommerce plugin, you will be able to accept the following payment methods in your shop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Mastercard\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Visa\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verve\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bank Account\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Note\u003C\u002Fh4>\n\u003Cp>This plugin is meant to be used by merchants in Nigeria and Ghana.\u003C\u002Fp>\n\u003Ch4>Plugin Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Accept payment\u003C\u002Fstrong> via Mastercard, Visa, Verve, Bank Accounts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless integration\u003C\u002Fstrong> into the WooCommerce checkout page. Accept payment directly on your site\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Refunds\u003C\u002Fstrong> from the WooCommerce order details page. Refund an order directly from the order details page\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recurring payment\u003C\u002Fstrong> using \u003Ca href=\"https:\u002F\u002Fwoocommerce.com\u002Fproducts\u002Fwoocommerce-subscriptions\u002F\" rel=\"nofollow ugc\">WooCommerce Subscriptions\u003C\u002Fa> plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WooCommerce Subscriptions Integration\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\n\u003Cp>The \u003Ca href=\"https:\u002F\u002Fwoocommerce.com\u002Fproducts\u002Fwoocommerce-subscriptions\u002F\" rel=\"nofollow ugc\">WooCommerce Subscriptions\u003C\u002Fa> integration only works with \u003Cstrong>WooCommerce v2.6 and above\u003C\u002Fstrong> and \u003Cstrong>WooCommerce Subscriptions v2.0 and above\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>No subscription plans is created on Monnify. The \u003Ca href=\"https:\u002F\u002Fwoocommerce.com\u002Fproducts\u002Fwoocommerce-subscriptions\u002F\" rel=\"nofollow ugc\">WooCommerce Subscriptions\u003C\u002Fa> plugin handles all the subscription functionality.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>If a customer pays for a subscription using a Mastercard or Visa card, their subscription will renew automatically throughout the duration of the subscription. If an automatic renewal fail their subscription will be put on-hold and they will have to login to their account to renew the subscription.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>For customers paying with a Verve card, their subscription can’t be renewed automatically, once a payment is due their subscription will be on-hold. The customer will have to login to his account to manually renew his subscription.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>If a subscription has a free trial and no signup-fee, automatic renewal is not possible for the first payment because the initial order total will be 0, after the free trial the subscription will be put on-hold. The customer will have to login to his account to renew his subscription. If a Mastercard or Visa card is used to renew the subscription subsequent renewals will be automatic throughout the duration of the subscription, if a Verve card is used automatic renewal isn’t possible.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Suggestions \u002F Feature Request\u003C\u002Fh4>\n\u003Cp>If you have suggestions or a new feature request, feel free to get in touch with me via the contact form on my website \u003Ca href=\"http:\u002F\u002Fadeleyeayodeji.com\u002F\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>You can also follow me on Twitter! \u003Cstrong>\u003Ca href=\"https:\u002F\u002Ftwitter.com\u002Fadeleyeayodeji_\" rel=\"nofollow ugc\">@adeleyeayodeji_\u003C\u002Fa>\u003C\u002Fstrong>\u003C\u002Fp>\n","Payment Gateway for Monnify on WooCommerce allows you to accept online payments from local and international customers",60,3456,"2026-05-06T12:22:00.000Z","6.9.5","5.6",[51,52,20,21,23],"adeleye-plugins","monnify","https:\u002F\u002Fwww.monnify.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmonnify-payment-gateway.zip",100,{"slug":57,"name":58,"version":59,"author":60,"author_profile":61,"description":62,"short_description":63,"active_installs":64,"downloaded":65,"rating":13,"num_ratings":13,"last_updated":66,"tested_up_to":67,"requires_at_least":68,"requires_php":69,"tags":70,"homepage":74,"download_link":75,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":76},"credo-payment-forms","Credo WooCommerce Payment Gateway","2.0.2","credocentral","https:\u002F\u002Fprofiles.wordpress.org\u002Fcredocentral\u002F","\u003Cp>Credo enables easier, intelligent, and rewarding payments for businesses and consumers alike, by combining the best of digital payments and digital innovation.\u003C\u002Fp>\n\u003Cp>With Credo for WooCommerce, you can accept payments via:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Credit\u002FDebit Cards:  Visa, Mastercard, Verve\u003C\u002Fli>\n\u003Cli>Bank transfer (Nigeria)\u003C\u002Fli>\n\u003Cli>Many more coming soon\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Why Credo?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Easy onboarding. Start receiving payments instantly. Go from sign-up to your first real transaction in as little as 5 minutes\u003C\u002Fli>\n\u003Cli>Settlement the way you want them.\u003C\u002Fli>\n\u003Cli>Simple, transparent pricing—no hidden charges or fees\u003C\u002Fli>\n\u003Cli>Advance fraud protection\u003C\u002Fli>\n\u003Cli>Your business growth our promise\u003C\u002Fli>\n\u003Cli>Understand your customers better through a simple and elegant dashboard\u003C\u002Fli>\n\u003Cli>Access to attentive, empathetic customer support 24\u002F7\u003C\u002Fli>\n\u003Cli>Free updates as we launch new features and payment options\u003C\u002Fli>\n\u003Cli>Integration as easy as ABC\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Sign up on \u003Ca href=\"https:\u002F\u002Fcredocentral.com\u002Fregister\" rel=\"nofollow ugc\">credocentral.com\u002Fregister\u003C\u002Fa> to get started.\u003C\u002Fp>\n\u003Ch4>Note\u003C\u002Fh4>\n\u003Cp>This plugin is meant to be used by merchants in Nigeria\u003C\u002Fp>\n\u003Ch4>Plugin Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Accept payment\u003C\u002Fstrong> via Mastercard, Visa, Verve and Bank Transfer,\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless integration\u003C\u002Fstrong> into the WooCommerce checkout page. Accept payment directly on your site\u003C\u002Fli>\n\u003C\u002Ful>\n","Credo enables easier, intelligent, and rewarding payments for businesses and consumers alike, by combining the best of digital payments and digital in &hellip;",10,4745,"2024-06-05T16:09:00.000Z","6.5.8","5.8","7.4",[71,72,21,73,23],"credo","payment-gateway-mastercard","visa","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcredo-payment-forms","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcredo-payment-forms.zip","2026-04-16T10:56:18.058Z",{"slug":78,"name":79,"version":80,"author":81,"author_profile":82,"description":83,"short_description":84,"active_installs":13,"downloaded":85,"rating":13,"num_ratings":13,"last_updated":86,"tested_up_to":87,"requires_at_least":16,"requires_php":88,"tags":89,"homepage":92,"download_link":93,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"paythru-payment-gateway","Paythru Payment Gateway","1.0.0","pethahiah01","https:\u002F\u002Fprofiles.wordpress.org\u002Fpethahiah01\u002F","\u003Cp>This is a Paythru payment gateway for WooCommerce.\u003C\u002Fp>\n\u003Cp>Paythru is on a mission to deliver a safe and convenient payment experience for customers and merchants.\u003C\u002Fp>\n\u003Cp>To signup for a Paythru Merchant account visit their website by clicking \u003Ca href=\"https:\u002F\u002FPaythru.ng\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Paythru WooCommerce Payment Gateway allows you to accept payment on your WooCommerce store using Mastercard, Visa, Verve, bank accounts, GTB 737 & Visa QR.\u003C\u002Fp>\n\u003Cp>With this Paythru WooCommerce Payment Gateway plugin, you will be able to accept the following payment methods in your shop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Mastercard\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Visa\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verve\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bank Account\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Note\u003C\u002Fh4>\n\u003Cp>This plugin is meant to be used by merchants in Nigeria.\u003C\u002Fp>\n\u003Ch4>Plugin Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Accept payment\u003C\u002Fstrong> via Mastercard, Visa, Verve, Bank Accounts\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless integration\u003C\u002Fstrong> into the WooCommerce checkout page. Accept payment directly on your site\u003C\u002Fli>\n\u003C\u002Ful>\n","Paythru WooCommerce Payment Gateway allows you to accept online payments from local and international customers",1265,"2022-07-10T21:49:00.000Z","6.0.12","",[90,20,91,21,23],"nigeria","paythru","https:\u002F\u002Fpaythru.ng\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fpaythru-payment-gateway.1.0.0.zip",{"slug":95,"name":96,"version":80,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":13,"downloaded":101,"rating":13,"num_ratings":13,"last_updated":102,"tested_up_to":103,"requires_at_least":16,"requires_php":49,"tags":104,"homepage":107,"download_link":108,"security_score":26,"vuln_count":13,"unpatched_count":13,"last_vuln_date":27,"fetched_at":28},"xpresspay-payment-gateway","XpressPay Payment Gateway","xpresspay","https:\u002F\u002Fprofiles.wordpress.org\u002Fxpresspay\u002F","\u003Cp>This is a Xpress Payments payment gateway for WooCommerce.\u003C\u002Fp>\n\u003Cp>Xpress Payments is on a mission to deliver a secure and seemless payment experience for customers and merchants.\u003C\u002Fp>\n\u003Cp>To signup visit our website by clicking \u003Ca href=\"https:\u002F\u002Fwww.xpresspayments.com\u002F\" rel=\"nofollow ugc\">here\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>XpressPay Payment Gateway allows you to accept payment on your WooCommerce store using Mastercard, Visa, Verve, USSD, QR, Bank Transfer & Bank Accounts.\u003C\u002Fp>\n\u003Cp>With this XpressPay Payment Gateway plugin, you will be able to accept the following payment methods in your shop:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Mastercard\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Visa\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Verve\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>USSD\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>QR\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bank Transfer\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bank Accounts\u003C\u002Fstrong>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Note\u003C\u002Fh4>\n\u003Cp>Implementing this plugin accepts payments into Nigerian Naira (NGN) accounts only.\u003C\u002Fp>\n\u003Ch4>Plugin Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Accept payment\u003C\u002Fstrong> via Mastercard, Visa, Verve, USSD, QR, Bank Transfer & Bank Accounts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless integration\u003C\u002Fstrong> into the WooCommerce checkout page. Accept payment directly on your site\u003C\u002Fli>\n\u003C\u002Ful>\n","XpressPay Payment Gateway allows you to accept online payments on your Woocommerce store via Visa Cards, Mastercards, Verve Cards, Bank Transfer, USSD &hellip;",1556,"2022-02-14T20:22:00.000Z","5.9.13",[20,105,23,97,106],"verve-cards","xpresspay-plugins","https:\u002F\u002Fgithub.com\u002Fmuyiwer\u002FXpressPayPlugin","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fxpresspay-payment-gateway.1.0.0.zip",{"slug":110,"name":111,"version":112,"author":113,"author_profile":114,"description":115,"short_description":116,"active_installs":117,"downloaded":118,"rating":119,"num_ratings":120,"last_updated":121,"tested_up_to":122,"requires_at_least":68,"requires_php":17,"tags":123,"homepage":126,"download_link":127,"security_score":128,"vuln_count":32,"unpatched_count":13,"last_vuln_date":129,"fetched_at":28},"zarinpal-woocommerce-payment-gateway","افزونه پرداخت امن زرین‌پال برای ووکامرس (ZarinPal for WooCommerce)","5.1.1","zarinpal","https:\u002F\u002Fprofiles.wordpress.org\u002Fzarinpal\u002F","\u003Cp>\u003Cstrong>ZarinPal Payment Gateway for WooCommerce\u003C\u002Fstrong> lets you easily set up the ZarinPal online payment gateway to accept payments for your WooCommerce store.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Automatically adds the Iranian Rial, Toman, thousand-Rial, and thousand-Toman currencies to WooCommerce\u003C\u002Fli>\n\u003Cli>Simple, user-friendly settings panel\u003C\u002Fli>\n\u003Cli>Customizable messages for successful, cancelled, or failed payments\u003C\u002Fli>\n\u003Cli>Displays the ZarinPal tracking code via a shortcode\u003C\u002Fli>\n\u003Cli>Displays payment gateway errors\u003C\u002Fli>\n\u003Cli>Optional sandbox (test) mode\u003C\u002Fli>\n\u003Cli>Transaction refund support\u003C\u002Fli>\n\u003Cli>Transaction detail lookup from the order screen\u003C\u002Fli>\n\u003Cli>Choose whether the gateway fee is paid by the merchant or the customer\u003C\u002Fli>\n\u003C\u002Ful>\n","Accept online payments through the ZarinPal payment gateway, the leading Iranian payment service provider, directly in WooCommerce.",50000,714367,70,13,"2026-07-15T11:28:00.000Z","7.0.2",[20,23,113,124,125],"%d8%af%d8%b1%da%af%d8%a7%d9%87-%d9%be%d8%b1%d8%af%d8%a7%d8%ae%d8%aa","%d8%b2%d8%b1%db%8c%d9%86%d9%be%d8%a7%d9%84","https:\u002F\u002Fzarinpal.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzarinpal-woocommerce-payment-gateway.5.1.1.zip",98,"2026-02-16 16:35:00",{"attackSurface":131,"codeSignals":187,"taintFlows":208,"riskAssessment":249,"analyzedAt":258},{"hooks":132,"ajaxHandlers":168,"restRoutes":183,"shortcodes":184,"cronEvents":185,"entryPointCount":186,"unprotectedCount":186},[133,139,143,147,151,157,161,165],{"type":134,"name":135,"callback":136,"file":137,"line":138},"action","wp_enqueue_scripts","payment_scripts","includes\\class-wc-vpay-gateway.php",62,{"type":134,"name":140,"callback":141,"file":137,"line":142},"admin_enqueue_scripts","admin_scripts",64,{"type":134,"name":144,"callback":145,"file":137,"line":146},"woocommerce_api_{webhook name}","webhook",68,{"type":134,"name":148,"callback":149,"file":137,"line":150},"woocommerce_api_wc_vpay_gateway","verify_vpay_payment",76,{"type":152,"name":153,"callback":154,"file":155,"line":156},"filter","woocommerce_payment_gateways","vpay_add_gateway_class","wc-vpay.php",24,{"type":134,"name":158,"callback":159,"file":155,"line":160},"plugins_loaded","vpay_init_gateway_class",33,{"type":134,"name":162,"callback":163,"file":155,"line":164},"admin_notices","vpay_wc_missing_notice",36,{"type":134,"name":162,"callback":166,"file":155,"line":167},"vpay_wc_testmode_notice",40,[169,174,177,181],{"action":170,"nopriv":171,"callback":170,"hasNonce":171,"hasCapCheck":171,"file":172,"line":173},"pay_load",false,"includes\\json-receive.php",109,{"action":170,"nopriv":175,"callback":170,"hasNonce":171,"hasCapCheck":171,"file":172,"line":176},true,110,{"action":178,"nopriv":171,"callback":179,"hasNonce":171,"hasCapCheck":171,"file":172,"line":180},"vpay_callback","webhook_callback",111,{"action":178,"nopriv":175,"callback":179,"hasNonce":171,"hasCapCheck":171,"file":172,"line":182},112,[],[],[],4,{"dangerousFunctions":188,"sqlUsage":189,"outputEscaping":192,"fileOperations":190,"externalRequests":32,"nonceChecks":13,"capabilityChecks":32,"bundledLibraries":207},[],{"prepared":190,"raw":13,"locations":191},2,[],{"escaped":120,"rawEcho":193,"locations":194},6,[195,198,200,202,204,206],{"file":137,"line":196,"context":197},129,"raw output",{"file":137,"line":199,"context":197},430,{"file":137,"line":201,"context":197},443,{"file":137,"line":203,"context":197},474,{"file":155,"line":205,"context":197},53,{"file":155,"line":119,"context":197},[],[209,227,235],{"entryPoint":210,"graph":211,"unsanitizedCount":32,"severity":226},"verify_vpay_payment (includes\\order-complete.php:6)",{"nodes":212,"edges":224},[213,219],{"id":214,"type":215,"label":216,"file":217,"line":218},"n0","source","$_REQUEST","includes\\order-complete.php",19,{"id":220,"type":221,"label":222,"file":217,"line":218,"wp_function":223},"n1","sink","file_put_contents() [File Write]","file_put_contents",[225],{"from":214,"to":220,"sanitized":171},"medium",{"entryPoint":228,"graph":229,"unsanitizedCount":32,"severity":226},"\u003Corder-complete> (includes\\order-complete.php:0)",{"nodes":230,"edges":233},[231,232],{"id":214,"type":215,"label":216,"file":217,"line":218},{"id":220,"type":221,"label":222,"file":217,"line":218,"wp_function":223},[234],{"from":214,"to":220,"sanitized":171},{"entryPoint":236,"graph":237,"unsanitizedCount":13,"severity":248},"\u003Cjson-receive> (includes\\json-receive.php:0)",{"nodes":238,"edges":246},[239,242],{"id":214,"type":215,"label":240,"file":172,"line":241},"$_POST",3,{"id":220,"type":221,"label":243,"file":172,"line":244,"wp_function":245},"get_col() [SQLi]",61,"get_col",[247],{"from":214,"to":220,"sanitized":175},"low",{"summary":250,"deductions":251},"The \"wc-vpay\" v1.1.0 plugin exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and a reasonable output escaping rate, the presence of four AJAX handlers without any authentication or capability checks presents a significant attack surface. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure.\n\nThe static analysis did not reveal critical or high-severity taint flows, which is a positive sign. However, the two flows with unsanitized paths, even if not categorized as critical, warrant attention as they indicate potential weaknesses that could be exploited in conjunction with other factors. The absence of nonce checks on these AJAX endpoints exacerbates this risk, as it further simplifies the exploitation process.\n\nThe plugin's vulnerability history is notably clean, with no recorded CVEs. This suggests that, historically, it has not been a significant target for widespread vulnerabilities. However, a clean history does not equate to current invulnerability, especially given the identified unprotected entry points. The plugin's strengths lie in its SQL handling and reasonable output escaping, but these are overshadowed by the critical flaw of exposed AJAX endpoints. A balanced conclusion is that while the plugin hasn't had public security issues, its current implementation contains significant, readily exploitable vulnerabilities due to lack of authentication on its AJAX actions.",[252,254,256],{"reason":253,"points":11},"4 AJAX handlers without auth checks",{"reason":255,"points":64},"2 flows with unsanitized paths",{"reason":257,"points":64},"0 nonce checks","2026-03-16T22:32:00.896Z",{"wat":260,"direct":270},{"assetPaths":261,"generatorPatterns":263,"scriptPaths":264,"versionParams":267},[262],"\u002Fwp-content\u002Fplugins\u002Fwc-vpay\u002Fassets\u002Fimages\u002Fvpay.svg",[],[265,266],"\u002Fwp-content\u002Fplugins\u002Fwc-vpay\u002Fassets\u002Fjs\u002Ffrontend\u002Fpayment.js","\u002Fwp-content\u002Fplugins\u002Fwc-vpay\u002Fassets\u002Fjs\u002Fbackend\u002Fadmin.js",[268,269],"wc-vpay\u002Fwc-vpay.php?ver=","wc-vpay\u002Fincludes\u002Fclass-wc-vpay-gateway.php?ver=",{"cssClasses":271,"htmlComments":275,"htmlAttributes":276,"restEndpoints":280,"jsGlobals":282,"shortcodeOutput":284},[272,273,274],"vpay-payment-form","vpay-error","vpay-test-mode-notice",[],[277,278,279],"data-vpay-public-key","data-vpay-amount","data-vpay-order-id",[281],"\u002Fwp-json\u002Fwc\u002Fv1\u002Fvpay\u002Fpayment-status",[283],"vpay_params",[285],"[vpay_payment_button]",{"error":175,"url":287,"statusCode":288,"statusMessage":289,"message":289},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fwc-vpay\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":190,"versions":291},[292,298],{"version":293,"download_url":25,"svn_tag_url":294,"released_at":27,"has_diff":171,"diff_files_changed":295,"diff_lines":27,"trac_diff_url":296,"vulnerabilities":297,"is_current":171},"1.2","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwc-vpay\u002Ftags\u002F1.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwc-vpay%2Ftags%2F1.1&new_path=%2Fwc-vpay%2Ftags%2F1.2",[],{"version":299,"download_url":300,"svn_tag_url":301,"released_at":27,"has_diff":171,"diff_files_changed":302,"diff_lines":27,"trac_diff_url":27,"vulnerabilities":303,"is_current":171},"1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwc-vpay.1.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwc-vpay\u002Ftags\u002F1.1\u002F",[],[]]