
MultiVendorX Razorpay Split Payment Security & Risk Analysis
wordpress.org/plugins/wcmp-razorpay-split-paymentThe much awaited MVX Razorpay Split Payment is now live.
Is MultiVendorX Razorpay Split Payment Safe to Use in 2026?
Generally Safe
Score 85/100MultiVendorX Razorpay Split Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wcmp-razorpay-split-payment plugin v1.0.2 exhibits a generally good security posture with no known vulnerabilities in its history and a limited attack surface. The static analysis reveals no dangerous functions, no direct SQL queries (all prepared), and no external HTTP requests, which are all positive signs. However, there are areas for improvement that present potential risks.
The primary concern lies in the output escaping. With 7 total outputs and only 43% properly escaped, there's a significant chance of cross-site scripting (XSS) vulnerabilities if the unescaped outputs contain user-supplied data. Additionally, the absence of nonce checks and capability checks on any potential entry points, though the attack surface is reported as zero, raises a flag. If any entry points were to be introduced or discovered, they would be unprotected.
Given the complete lack of recorded vulnerabilities, the plugin's history doesn't indicate any past weaknesses. However, the current code analysis highlights the potential for XSS and the lack of robust authorization for any hypothetical future entry points. The overall conclusion is that the plugin is currently safe based on its history, but the identified code-level weaknesses, particularly in output escaping, require attention to maintain a strong security posture.
Key Concerns
- Insufficient output escaping
- Missing nonce checks
- Missing capability checks
MultiVendorX Razorpay Split Payment Security Vulnerabilities
MultiVendorX Razorpay Split Payment Code Analysis
Output Escaping
MultiVendorX Razorpay Split Payment Attack Surface
WordPress Hooks 18
Maintenance & Trust
MultiVendorX Razorpay Split Payment Maintenance & Trust
Maintenance Signals
Community Trust
MultiVendorX Razorpay Split Payment Alternatives
MultiVendorX Cointopay Gateway
mvx-cointopay-gateway
A Free Payment Gateway for WC Marketplace allowing you to Pay Your Vendors Using Cointopay.
WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors
wc-vendors
The original WooCommerce multi-vendor plugin. Easily create a WooCommerce marketplace with multi-seller, product vendor stores & vendor commissions.
Commission Widget for Dokan
commission-widget-for-dokan
Commission Widget for Dokan displays the Vendor Commission on Dokan Vendor Dashboard.
MarketEngine
marketengine
A free WordPress plugin that allows you to build a multi vendor marketplace platform for any niche.
Smart Affiliate for Dokan
smart-affiliate-for-dokan
A robust affiliate marketing system for WooCommerce and Dokan, allowing vendors to manage affiliate links and track commissions effortlessly.
MultiVendorX Razorpay Split Payment Developer Profile
5 plugins · 13K total installs
How We Detect MultiVendorX Razorpay Split Payment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wcmp-razorpay-split-payment/assets/css/mvx-razorpay-checkout-gateway.css/wp-content/plugins/wcmp-razorpay-split-payment/assets/js/mvx-razorpay-checkout-gateway.js/wp-content/plugins/wcmp-razorpay-split-payment/assets/js/mvx-razorpay-checkout-script.js/wp-content/plugins/wcmp-razorpay-split-payment/assets/css/mvx-razorpay-checkout-gateway.css?ver=/wp-content/plugins/wcmp-razorpay-split-payment/assets/js/mvx-razorpay-checkout-gateway.js?ver=/wp-content/plugins/wcmp-razorpay-split-payment/assets/js/mvx-razorpay-checkout-script.js?ver=HTML / DOM Fingerprints
data-razorpay-key-iddata-razorpay-amountdata-razorpay-order-iddata-razorpay-currencydata-razorpay-imagedata-razorpay-name+8 moreRazorpaymvx_razorpay_checkout_params[mvx_razorpay_payment]