Boring-IT Paypal.me Gateway Security & Risk Analysis

wordpress.org/plugins/woo-paypal-me-payment

Use Paypal.Me as payment method in your woocommerce shop.

10 active installs v1.0.0 PHP 7.0.0+ WP 3.5+ Updated Mar 18, 2019
gatewaypaymentwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Boring-IT Paypal.me Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Boring-IT Paypal.me Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "woo-paypal-me-payment" v1.0.0 exhibits a mixed security posture. On the positive side, there are no identified CVEs, no known vulnerabilities, and the code analysis shows no dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries are properly prepared, which is a strong indicator of secure database interaction. However, there are significant concerns regarding output escaping, with a substantial 100% of outputs being unescaped. This is a serious risk, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the plugin's output, which could then be executed by users' browsers. The absence of nonce checks and capability checks on its limited entry points (which are zero in this analysis) also represents a missed opportunity for robust access control and protection against Cross-Site Request Forgery (CSRF) attacks, though the lack of entry points mitigates this immediate risk.

Key Concerns

  • Unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Boring-IT Paypal.me Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Boring-IT Paypal.me Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Boring-IT Paypal.me Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedboring-it-paypal-me-payment.php:11
actionwp_enqueue_scriptsboring-it-paypal-me-payment.php:12
actionadmin_enqueue_scriptsboring-it-paypal-me-payment.php:13
filterwoocommerce_payment_gatewaysboring-it-paypal-me-payment.php:14
actionwoocommerce_update_options_payment_gatewaysboring-it-paypal-me-payment.php:53
actionwoocommerce_thankyouboring-it-paypal-me-payment.php:54
actionwoocommerce_email_before_order_tableboring-it-paypal-me-payment.php:56
Maintenance & Trust

Boring-IT Paypal.me Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 18, 2019
PHP min version7.0.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Boring-IT Paypal.me Gateway Developer Profile

Boring-IT

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Boring-IT Paypal.me Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-paypal-me-payment/woocommerce-paypal-me.php

HTML / DOM Fingerprints

CSS Classes
bit_paypal_me_button_backendbit_admin_descpaypal_me_containerpaypal_me_button
FAQ

Frequently Asked Questions about Boring-IT Paypal.me Gateway