Wenprise Alipay Gateway For WooCommerce Security & Risk Analysis

wordpress.org/plugins/wenprise-alipay-checkout-for-woocommerce

Alipay payment gateway for WooCommerce, WooCommerce 支付宝免费全功能支付网关。

700 active installs v2.0.1 PHP 7.2+ WP 4.7+ Updated Aug 4, 2024
alipayalipay-payment-gatewaywoocommercewoocommerce-payment-gateway%e6%94%af%e4%bb%98%e5%ae%9d%e6%94%af%e4%bb%98
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wenprise Alipay Gateway For WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Wenprise Alipay Gateway For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of wenprise-alipay-checkout-for-woocommerce v2.0.1 reveals a plugin with a very small attack surface and no immediate critical vulnerabilities identified in the provided data. The absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a limited scope of interaction, which is generally a positive security indicator. The code analysis also shows a complete absence of dangerous functions and SQL queries are all secured with prepared statements. File operations and external HTTP requests are also not present, further reducing potential attack vectors.

However, a significant concern arises from the extremely low output escaping percentage (14%), indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on any identified entry points (though none were found, which is itself a potential oversight if the plugin has any hidden entry points) is also a weakness. The bundled Guzzle library, while not explicitly stated as outdated, represents a dependency that could harbor vulnerabilities if not managed and updated. The vulnerability history being empty is positive, but it's crucial to note that this may not always reflect the actual state of security and could be due to a lack of past public disclosures or diligent patching.

In conclusion, while the plugin appears to have a minimal attack surface and no direct critical code flaws, the extremely poor output escaping practices present a substantial risk of XSS vulnerabilities. The lack of authentication checks on potential entry points and the presence of a bundled library also warrant careful consideration. Organizations using this plugin should prioritize addressing the output escaping issues and ensure robust sanitization and validation of all user-provided data.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
  • Bundled outdated library (potential risk)
Vulnerabilities
None known

Wenprise Alipay Gateway For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wenprise Alipay Gateway For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
6
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle1.1

SQL Query Safety

100% prepared1 total queries

Output Escaping

14% escaped7 total outputs
Attack Surface

Wenprise Alipay Gateway For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionwoocommerce_rest_checkout_process_payment_with_contextsrc\BlockSupport.php:22
actionwc_gateway_alipay_process_payment_errorsrc\BlockSupport.php:89
actionwoocommerce_blocks_loadedsrc\Init.php:11
actionbefore_woocommerce_initsrc\Init.php:12
actionwp_enqueue_scriptssrc\Init.php:13
actionadmin_enqueue_scriptssrc\Init.php:14
filteroption_trp_advanced_settingssrc\Init.php:16
filtertrp_no_translate_selectorssrc\Init.php:17
filterwoocommerce_pay_order_button_htmlsrc\Init.php:19
actionwoocommerce_blocks_payment_method_type_registrationsrc\Init.php:29
actionadmin_noticessrc\PaymentGateway.php:161
actionwoocommerce_api_wprs-wc-alipay-returnsrc\PaymentGateway.php:164
actionwoocommerce_api_wprs-wc-alipay-notifysrc\PaymentGateway.php:165
actionwoocommerce_api_wprs-wc-query-ordersrc\PaymentGateway.php:166
actionadmin_noticeswenprise-alipay-checkout-for-woocommerce.php:27
actionplugins_loadedwenprise-alipay-checkout-for-woocommerce.php:47
filterwoocommerce_payment_gatewayswenprise-alipay-checkout-for-woocommerce.php:61
Maintenance & Trust

Wenprise Alipay Gateway For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedAug 4, 2024
PHP min version7.2
Downloads27K

Community Trust

Rating100/100
Number of ratings1
Active installs700
Developer Profile

Wenprise Alipay Gateway For WooCommerce Developer Profile

Amos Lee(一刀)

8 plugins · 5K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wenprise Alipay Gateway For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/styles.css/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/scripts.js/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/admin.js
Script Paths
/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/scripts.js/wp-content/plugins/wenprise-alipay-checkout-for-woocommerce/frontend/admin.js
Version Parameters
wenprise-alipay-checkout-for-woocommerce/frontend/styles.css?ver=wenprise-alipay-checkout-for-woocommerce/frontend/scripts.js?ver=wenprise-alipay-checkout-for-woocommerce/frontend/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc-alipay-payment-url
Data Attributes
name="wc-alipay-payment-url"
JS Globals
WpWooAlipayData
REST Endpoints
/wp-json/wprs-wc-alipay/v1/query-order
FAQ

Frequently Asked Questions about Wenprise Alipay Gateway For WooCommerce