Instamojo for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-instamojo

Sell & collect payments instantly for almost anything -- directly from your WordPress website.

5K active installs v2.0.1 PHP + WP 4.6+ Updated May 6, 2024
commercee-commerceeasy-paymentspayment-gatewaypayments
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Instamojo for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Instamojo for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "woo-instamojo" v2.0.1 plugin presents a mixed security picture. On the positive side, the static analysis reveals a complete lack of identified attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that are not protected by authentication or capability checks. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. There is also no record of past vulnerabilities, which is a strong indicator of a well-maintained and secure plugin over its history.

However, a significant concern is the complete absence of output escaping. With two total outputs analyzed and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-supplied data that is later displayed on the website. The lack of nonce checks and capability checks, while not immediately tied to specific entry points in this analysis, suggests a potential gap in securing interactions if new entry points were introduced or if these checks are implicitly relied upon rather than explicitly implemented.

In conclusion, while the plugin excels in protecting its entry points and database interactions, the critical failure in output escaping poses a substantial XSS risk. The absence of known historical vulnerabilities is encouraging, but the static analysis highlights a specific, exploitable weakness that needs immediate attention. The plugin's strengths lie in its limited attack surface and secure data handling, but its weakness in output sanitization is a major security concern.

Key Concerns

  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Instamojo for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Instamojo for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Instamojo for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterquery_varswoo-instamojo.php:50
actionplugins_loadedwoo-instamojo.php:72
actiontemplate_redirectwoo-instamojo.php:212
filterwoocommerce_payment_gatewayswoo-instamojo.php:222
actionwoocommerce_blocks_loadedwoo-instamojo.php:228
actionwoocommerce_blocks_payment_method_type_registrationwoo-instamojo.php:239
actionbefore_woocommerce_initwoo-instamojo.php:255
actionbefore_woocommerce_initwoo-instamojo.php:261
Maintenance & Trust

Instamojo for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 6, 2024
PHP min version
Downloads186K

Community Trust

Rating62/100
Number of ratings13
Active installs5K
Developer Profile

Instamojo for WooCommerce Developer Profile

Instamojo

1 plugin · 5K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Instamojo for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-instamojo/instamojo-settings.php/wp-content/plugins/woo-instamojo/lib/Instamojo.php

HTML / DOM Fingerprints

CSS Classes
woocommerce-error
Data Attributes
data-instamojo-order-iddata-instamojo-payment-id
FAQ

Frequently Asked Questions about Instamojo for WooCommerce