
Wenprise Alipay Gateway For WooCommerce Security & Risk Analysis
wordpress.org/plugins/wenprise-alipay-checkout-for-woocommerceAlipay payment gateway for WooCommerce, WooCommerce 支付宝免费全功能支付网关。
Is Wenprise Alipay Gateway For WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Wenprise Alipay Gateway For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wenprise-alipay-checkout-for-woocommerce v2.0.1 reveals a plugin with a very small attack surface and no immediate critical vulnerabilities identified in the provided data. The absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a limited scope of interaction, which is generally a positive security indicator. The code analysis also shows a complete absence of dangerous functions and SQL queries are all secured with prepared statements. File operations and external HTTP requests are also not present, further reducing potential attack vectors.
However, a significant concern arises from the extremely low output escaping percentage (14%), indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on any identified entry points (though none were found, which is itself a potential oversight if the plugin has any hidden entry points) is also a weakness. The bundled Guzzle library, while not explicitly stated as outdated, represents a dependency that could harbor vulnerabilities if not managed and updated. The vulnerability history being empty is positive, but it's crucial to note that this may not always reflect the actual state of security and could be due to a lack of past public disclosures or diligent patching.
In conclusion, while the plugin appears to have a minimal attack surface and no direct critical code flaws, the extremely poor output escaping practices present a substantial risk of XSS vulnerabilities. The lack of authentication checks on potential entry points and the presence of a bundled library also warrant careful consideration. Organizations using this plugin should prioritize addressing the output escaping issues and ensure robust sanitization and validation of all user-provided data.
Key Concerns
- Low output escaping percentage
- No nonce checks
- No capability checks
- Bundled outdated library (potential risk)
Wenprise Alipay Gateway For WooCommerce Security Vulnerabilities
Wenprise Alipay Gateway For WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Wenprise Alipay Gateway For WooCommerce Attack Surface
WordPress Hooks 17
Maintenance & Trust
Wenprise Alipay Gateway For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Wenprise Alipay Gateway For WooCommerce Alternatives
Invoice Gateway for WooCommerce – Invoice Payment Gateway
invoice-gateway-for-woocommerce
Add a WooCommerce invoice gateway to your store. An easy invoicing payment gateway solution for WooCommerce.
PayPlus Payment Gateway
payplus-payment-gateway
Accept credit/debit card payments or other methods such as bit, Apple Pay, Google Pay in one page. Create digitally signed invoices & much more!
Helcim Commerce for WooCommerce
helcim-commerce-for-woocommerce
Helcim Payment Module for WooCommerce
Payment Gateway – 2Checkout for WooCommerce
woo-2checkout
2Checkout Payment Gateway for WooCommerce allow to accept online store payment from Paypal, Credit Card, MasterCard and more.
Wenprise WeChatPay Payment Gateway For WooCommerce
wenprise-wechatpay-checkout-for-woocommerce
WeChat payment gateway for WooCommerce, WooCommerce 微信免费全功能支付网关。
Wenprise Alipay Gateway For WooCommerce Developer Profile
8 plugins · 5K total installs
How We Detect Wenprise Alipay Gateway For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/styles.css/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/scripts.js/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/admin.js/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/scripts.js/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/admin.jswenprise-alipay-checkout-for-woocommerce/frontend/styles.css?ver=wenprise-alipay-checkout-for-woocommerce/frontend/scripts.js?ver=wenprise-alipay-checkout-for-woocommerce/frontend/admin.js?ver=HTML / DOM Fingerprints
wc-alipay-payment-urlname="wc-alipay-payment-url"WpWooAlipayData/wp-json/wprs-wc-alipay/v1/query-order