Webmoney – payment gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-webmoney

Allows you to use the Webmoney with WooCommerce as a payment gateway plugin.

100 active installs v2.0.1.1 PHP 5.4+ WP 3.0+ Updated Oct 5, 2019
ecommercepayment-gatewaywebmoneywoo-commercewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webmoney – payment gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Webmoney – payment gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "wc-webmoney" plugin v2.0.1.1 demonstrates a generally good security posture with no known vulnerabilities or critical/high severity taint flows. The static analysis indicates a limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. This suggests a deliberate effort by the developers to restrict entry points. The presence of capability checks, though limited, is a positive sign. However, the analysis does reveal some areas of concern. A significant portion of output (57%) is not properly escaped, posing a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization. Furthermore, the single SQL query identified is not using prepared statements, which can lead to SQL injection vulnerabilities if not handled with extreme care. The single file operation and unsanitized path in the taint analysis also warrant attention, as these could be leveraged in certain attack scenarios. While the vulnerability history is clean, the code-level weaknesses suggest that the plugin's security is not as robust as its lack of past vulnerabilities might imply. Continued vigilance and code improvements are recommended.

Key Concerns

  • SQL queries not using prepared statements
  • Insufficient output escaping
  • Flows with unsanitized paths
Vulnerabilities
None known

Webmoney – payment gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Webmoney – payment gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
8
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

43% escaped14 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
input_payment_notifications (includes\class-wc-webmoney-method.php:1061)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Webmoney – payment gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:135
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:136
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:137
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:138
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:139
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:140
filterwc_webmoney_init_form_fieldsincludes\class-wc-webmoney-method.php:141
actionwc_webmoney_payment_fields_showincludes\class-wc-webmoney-method.php:152
actionwc_webmoney_payment_fields_after_showincludes\class-wc-webmoney-method.php:157
actionwc_webmoney_receipt_page_showincludes\class-wc-webmoney-method.php:162
actionwoocommerce_initincludes\class-wc-webmoney.php:182
filterwoocommerce_payment_gatewaysincludes\class-wc-webmoney.php:187
actionadmin_enqueue_scriptsincludes\class-wc-webmoney.php:197
actionadmin_noticesincludes\class-wc-webmoney.php:202
filterplugin_row_metaincludes\class-wc-webmoney.php:208
actionwc_webmoney_admin_options_form_before_showincludes\class-wc-webmoney.php:432
actionwc_webmoney_admin_options_form_after_showincludes\class-wc-webmoney.php:433
actionwc_webmoney_admin_options_form_right_column_showincludes\class-wc-webmoney.php:434
actionwc_webmoney_admin_options_form_right_column_showincludes\class-wc-webmoney.php:435
actionplugins_loadedwc-webmoney.php:27
Maintenance & Trust

Webmoney – payment gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 5, 2019
PHP min version5.4
Downloads15K

Community Trust

Rating100/100
Number of ratings5
Active installs100
Developer Profile

Webmoney – payment gateway for WooCommerce Developer Profile

Mofsy

2 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webmoney – payment gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-webmoney/assets/css/wc-webmoney.css/wp-content/plugins/wc-webmoney/assets/js/wc-webmoney.js
Script Paths
/wp-content/plugins/wc-webmoney/assets/js/wc-webmoney.js
Version Parameters
wc-webmoney.css?ver=wc-webmoney.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc-webmoney-admin-settings
HTML Comments
Mofsy <support@mofsy.ru> https://mofsy.ru
FAQ

Frequently Asked Questions about Webmoney – payment gateway for WooCommerce