
Wenprise WeChatPay Payment Gateway For WooCommerce Security & Risk Analysis
wordpress.org/plugins/wenprise-wechatpay-checkout-for-woocommerceWeChat payment gateway for WooCommerce, WooCommerce 微信免费全功能支付网关。
Is Wenprise WeChatPay Payment Gateway For WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Wenprise WeChatPay Payment Gateway For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wenprise-wechatpay-checkout-for-woocommerce v2.1.0 reveals a plugin with a very limited attack surface, as indicated by zero AJAX handlers, REST API routes, shortcodes, and cron events. This is a positive sign, suggesting a reduced potential for direct exploitation. However, the code signals raise significant concerns. The fact that 50% of SQL queries are not using prepared statements is a serious risk, potentially leading to SQL injection vulnerabilities. Furthermore, only 7% of output is properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks on the plugin's entry points is also a major security weakness, leaving functionality open to unauthorized access and manipulation. Taint analysis shows flows with unsanitized paths, although no critical or high severity issues were identified in this specific analysis run, the pattern is concerning given the other code quality issues. The absence of any recorded vulnerabilities in its history is a strength, but this should not overshadow the evident weaknesses in the current code. In conclusion, while the plugin has a small attack surface and no prior known vulnerabilities, the poor implementation of SQL query sanitization, output escaping, and the complete lack of authorization checks present substantial security risks.
Key Concerns
- 50% of SQL queries not using prepared statements
- Only 7% of output properly escaped
- 0 Nonce checks
- 0 Capability checks
- Taint analysis shows unsanitized paths
Wenprise WeChatPay Payment Gateway For WooCommerce Security Vulnerabilities
Wenprise WeChatPay Payment Gateway For WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Wenprise WeChatPay Payment Gateway For WooCommerce Attack Surface
WordPress Hooks 22
Maintenance & Trust
Wenprise WeChatPay Payment Gateway For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Wenprise WeChatPay Payment Gateway For WooCommerce Alternatives
Wenprise Alipay Gateway For WooCommerce
wenprise-alipay-checkout-for-woocommerce
Alipay payment gateway for WooCommerce, WooCommerce 支付宝免费全功能支付网关。
Due.com E-Commerce Payment Gateway
duecom-e-commerce-payment-gateway
Be sure to checkout our tutorial on using this plugin.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
Wenprise WeChatPay Payment Gateway For WooCommerce Developer Profile
8 plugins · 5K total installs
How We Detect Wenprise WeChatPay Payment Gateway For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wenprise-wechatpay-checkout-for-woocommerce/frontend/script.jswp-content/plugins/wenprise-wechatpay-checkout-for-woocommerce/frontend/script.jswenprise-wechatpay-checkout-for-woocommerce/frontend/script.js?ver=HTML / DOM Fingerprints
WpWooWechatData/wp-json/wprs-wc-wechatpay-query