
WePay Woocommerce addon Security & Risk Analysis
wordpress.org/plugins/woo-payment-addonThis plugin is an addon for WooCommerce to implement a payment gateway method for accepting Credit Cards Payments By merchants via WePay Payment Gatew …
Is WePay Woocommerce addon Safe to Use in 2026?
Generally Safe
Score 85/100WePay Woocommerce addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-payment-addon" v3.0.0 plugin exhibits a concerning security posture primarily due to a complete lack of output escaping, which is a significant vulnerability. While the static analysis reveals no dangerous functions, no SQL queries that are not prepared, and no file operations, the absence of any output escaping for the 6 identified outputs means that any data displayed to users could potentially be manipulated, leading to cross-site scripting (XSS) attacks. The plugin also makes an external HTTP request, which, without further context on what data is being sent and received, could pose a risk if the endpoint is compromised or the data is not properly handled. The plugin's history of zero known vulnerabilities is a positive sign, suggesting a potentially well-maintained codebase or a lack of focused attacks. However, this is heavily outweighed by the critical flaw in output sanitization. In conclusion, while the plugin avoids common pitfalls like raw SQL and a large attack surface, the unescaped output represents a severe weakness that requires immediate attention.
Key Concerns
- All outputs are unescaped
- External HTTP request without clear context
WePay Woocommerce addon Security Vulnerabilities
WePay Woocommerce addon Code Analysis
Output Escaping
WePay Woocommerce addon Attack Surface
WordPress Hooks 4
Maintenance & Trust
WePay Woocommerce addon Maintenance & Trust
Maintenance Signals
Community Trust
WePay Woocommerce addon Alternatives
Crowdfunding WePay oAuth 2.0 by Astoundify
edd-wepay-oauth2
Add WePay oAuth2 support for Easy Digital Downloads WePay and Crowdfunding by Astoundify.
WePay WordPress Plugin
wepay-wordpress-plugin
Allows you to use a Wepay account to accept payments easily online thru your wordpress installation. Easy install, drag and drop.
WP Thumbs Plugin
wp-thumbs
WP Thumbs is a voting plugin that allows users to like or dislike posts and pages. There are many customization options.
WePay Woocommerce addon Developer Profile
11 plugins · 600 total installs
How We Detect WePay Woocommerce addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-payment-addon/classes/wepay.phpHTML / DOM Fingerprints
/wc_wepay_gateway