
Whalet Payment Security & Risk Analysis
wordpress.org/plugins/whalet-paymentSecure and convenient online payment gateway for WordPress with WooCommerce integration and flexible payment solutions.
Is Whalet Payment Safe to Use in 2026?
Generally Safe
Score 100/100Whalet Payment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whalet-payment" v1.1.2 plugin demonstrates a generally good security posture, with strong adoption of prepared statements for SQL queries and proper output escaping, both exceeding 85%. The absence of known vulnerabilities and CVEs in its history is a significant positive indicator. The plugin also implements a substantial number of nonce and capability checks, suggesting a proactive approach to securing its functionalities.
However, a key concern arises from the attack surface analysis, which reveals 14 AJAX handlers, with 2 of them lacking authentication checks. This presents a direct risk of unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis identified 3 flows with unsanitized paths, although these did not reach critical or high severity levels. These flows, combined with the unprotected AJAX handlers, represent potential avenues for attackers to manipulate plugin behavior or access sensitive data, even if the immediate impact is not severe.
In conclusion, while "whalet-payment" exhibits many positive security practices, the presence of unprotected AJAX handlers and unsanitized code paths warrants attention. Addressing these specific weaknesses would significantly strengthen the plugin's overall security. The lack of historical vulnerabilities is reassuring, but it is crucial to address the identified immediate risks to maintain a robust security profile.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths detected
Whalet Payment Security Vulnerabilities
Whalet Payment Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Whalet Payment Attack Surface
AJAX Handlers 14
Shortcodes 3
WordPress Hooks 84
Scheduled Events 2
Maintenance & Trust
Whalet Payment Maintenance & Trust
Maintenance Signals
Community Trust
Whalet Payment Alternatives
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
MONEI Payments for WooCommerce
monei
Accept Card, Apple Pay, Google Pay, Bizum, PayPal and many more payment methods in your WooCommerce store using MONEI payment gateway.
FeexPay
feexpay
A secure plugin to accept Mobile Money and Credit Card payments.
Pay Advantage
pay-advantage
Instantly accept Visa, Mastercard and American Express from your site with fast settlement to any Australian bank account.
Beanstream for WooCommerce
beanstream-gateway-for-woocommerce
A Payment Gateway for WooCommerce allowing you to take credit card payments using Beanstream.
Whalet Payment Developer Profile
1 plugin · 0 total installs
How We Detect Whalet Payment
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whalet-payment/assets/css/whalet-admin.css/wp-content/plugins/whalet-payment/assets/css/whalet-refund.css/wp-content/plugins/whalet-payment/assets/js/whalet-admin.js/wp-content/plugins/whalet-payment/assets/js/whalet-payment.js/wp-content/plugins/whalet-payment/assets/js/whalet-admin.js/wp-content/plugins/whalet-payment/assets/js/whalet-payment.jswhalet-payment/assets/css/whalet-admin.css?ver=whalet-payment/assets/css/whalet-refund.css?ver=whalet-payment/assets/js/whalet-admin.js?ver=whalet-payment/assets/js/whalet-payment.js?ver=HTML / DOM Fingerprints
whalet_payment_ajax_object/wp-json/whalet-payment/v1/get-order/wp-json/whalet-payment/v1/capture-payment[whalet_payment_button]