Jenga Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-jenga-payment-gateway

Accept Cards, Mobile Money, and Bank Account Payments in a simple and convenient way from your customers on your store with Jenga Payment Gateway for …

30 active installs v3.0.15 PHP + WP 4.7+ Updated Dec 17, 2024
eccommercejengakenyapayment-gatewaywoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jenga Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Jenga Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "woo-jenga-payment-gateway" v3.0.15 plugin exhibits a generally good security posture with several positive indicators. The absence of known CVEs and a clean vulnerability history suggest a history of responsible development and maintenance. The code analysis reveals a strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and the vast majority of output being properly escaped. The plugin also avoids dangerous functions, file operations, and external HTTP requests, further contributing to a reduced attack surface.

However, there are specific areas for concern. The taint analysis highlights one high-severity flow with unsanitized paths, which is a significant risk. This indicates a potential for data manipulation or unintended execution if the input associated with this flow is not properly validated and sanitized before being used. Furthermore, the complete lack of nonce checks and capability checks is a critical oversight, especially given that these are fundamental WordPress security mechanisms. While the current attack surface (AJAX, REST API, shortcodes, cron) is reported as zero, this could change with future updates, and the absence of these checks would expose any new entry points.

In conclusion, while the plugin benefits from a clean history and good practices in areas like SQL and output escaping, the presence of a high-severity taint flow and the complete absence of nonce and capability checks represent substantial security weaknesses. These latter issues, in particular, indicate a lack of fundamental security awareness and could be easily exploited if any new entry points are introduced. Addressing the unsanitized taint flow and implementing nonce and capability checks are paramount to improving the plugin's security.

Key Concerns

  • High severity taint flow with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Jenga Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Jenga Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
3
64 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

96% escaped67 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
search_box (includes\jpgwpayments.php:90)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Jenga Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_headincludes\jpgwpayments.php:21
filterset-screen-optionincludes\jpgwpayments.php:195
actionadmin_menuincludes\jpgwpayments.php:196
actionplugins_loadedincludes\jpgwpayments.php:270
actionadmin_menuincludes\menu.php:11
actionadmin_menuincludes\menu.php:12
actionadmin_noticesjenga-payment-gateway-woocommerce.php:66
actionwoocommerce_receipt_jpgwjenga-payment-gateway-woocommerce.php:69
actionwoocommerce_thankyoujenga-payment-gateway-woocommerce.php:72
actionwoocommerce_api_wc_gateway_jpgwjenga-payment-gateway-woocommerce.php:75
actionwoocommerce_endpoint_order-received_titlejenga-payment-gateway.php:82
filterwoocommerce_thankyou_order_received_textjenga-payment-gateway.php:101
actionplugins_loadedjenga-payment-gateway.php:171
filterwoocommerce_payment_gatewaysjenga-payment-gateway.php:191
filterwoocommerce_price_trim_zerosjenga-payment-gateway.php:206
actionhttp_api_curljenga-payment-gateway.php:209
Maintenance & Trust

Jenga Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2024
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Jenga Payment Gateway for WooCommerce Developer Profile

jengapgw

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jenga Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-jenga-payment-gateway/jenga-payment-gateway-woocommerce.php

HTML / DOM Fingerprints

CSS Classes
woocommerce-tableshop_tablegift_info
FAQ

Frequently Asked Questions about Jenga Payment Gateway for WooCommerce