
Multiple Payment Gateways for WooCommerce (WCMPG) Security & Risk Analysis
wordpress.org/plugins/wcmpgWCMPG provides multiple payment gateways for WooCommerce.
Is Multiple Payment Gateways for WooCommerce (WCMPG) Safe to Use in 2026?
Generally Safe
Score 100/100Multiple Payment Gateways for WooCommerce (WCMPG) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wcmpg" v1.71 exhibits a concerning security posture primarily due to its lack of authentication and authorization checks on its entry points. The analysis reveals one unprotected AJAX handler, which presents a significant risk as unauthenticated users could potentially trigger its functionality. Furthermore, the presence of dangerous `exec` functions within the code signals a potential for remote code execution if these functions are reachable through an insecure entry point. While the plugin demonstrates good practices in SQL query handling by exclusively using prepared statements, and its vulnerability history is clean, these strengths are overshadowed by the critical deficiencies in securing its attack surface.
Key Concerns
- Unprotected AJAX handler
- Dangerous function 'exec' found
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
- High percentage of unsanitized paths in taint analysis
Multiple Payment Gateways for WooCommerce (WCMPG) Security Vulnerabilities
Multiple Payment Gateways for WooCommerce (WCMPG) Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Multiple Payment Gateways for WooCommerce (WCMPG) Attack Surface
AJAX Handlers 1
WordPress Hooks 17
Maintenance & Trust
Multiple Payment Gateways for WooCommerce (WCMPG) Maintenance & Trust
Maintenance Signals
Community Trust
Multiple Payment Gateways for WooCommerce (WCMPG) Alternatives
Fr Multi Bank Transfer Payment Gateways for WooCommerce
fr-multi-bank-transfer-payment-gateways-for-woocommerce
Add multiple bank transfer payment gateways.
Payment Gateway – nexi Alpha Bank for WooCommerce
woo-alpha-bank-payment-gateway
This Plugin adds Alpha Bank paycenter as a payment gateway for WooCommerce.
Advance Bank Payment Transfer Gateway
advance-bank-payment-transfer-gateway
Short Description: This plugin clones the Direct Bank Transfer gateway to create another offline payment method. License: GPLv2 or later
Payment Gateway bKash for WC
woo-payment-bkash
You can easily pay via bKash.
Direct Payments for WooCommerce – Bank Transfer, Mobile Money, Crypto and Peer-to-Peer (P2P) Payments
direct-payments-for-woocommerce
Direct Payments for WooCommerce allows your store to accept instant payments via bank transfers, mobile money, crypto and popular P2P platforms global …
Multiple Payment Gateways for WooCommerce (WCMPG) Developer Profile
5 plugins · 310 total installs
How We Detect Multiple Payment Gateways for WooCommerce (WCMPG)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wcmpg/admin/js/wcmpg-admin-script.js/wp-content/plugins/wcmpg/admin/css/wcmpg-admin-style.css/wp-content/plugins/wcmpg/includes/js/wcmpg-script.js/wp-content/plugins/wcmpg/includes/css/wcmpg-style.css/wp-content/plugins/wcmpg/admin/js/wcmpg-admin-script.js/wp-content/plugins/wcmpg/includes/js/wcmpg-script.jsHTML / DOM Fingerprints
wcmpg-licence-inputwcmpg-licence-save-buttonwcmpg-notice-dismisswcmpg-payment-gateway-settingsTODO removedata-wcmpg-gateway-iddata-wcmpg-order-iddata-wcmpg-actionwcmpg_ajax_object/wp-json/wcmpg/v1/settings/wp-json/wcmpg/v1/payment/status