Allow mobile banking (Bkash, Rocket), Visa & Mastercard payments within your woocommerce stores and wordpress. Paysenz combines the open mobile banking api, open visa api to bring you the latest in Payments.

10 active installs v1.0.1 PHP 5.6+ WP 4.0+ Updated Dec 10, 2019
bkashmastercardmobile-bankingpaysenzrocket
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paysenz Safe to Use in 2026?

Generally Safe

Score 85/100

Paysenz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of "woo-paysenz-payment-gateway" v1.0.1 reveals a plugin with a seemingly strong adherence to some security best practices. Notably, there are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. This indicates good practices in preventing common vulnerabilities like SQL injection and XSS at the output level. The absence of file operations and the use of prepared statements are positive signs. However, the complete lack of identified entry points (AJAX, REST API, shortcodes, cron events) is highly unusual and potentially indicates an incomplete or inaccurate analysis, or a plugin that has no user-facing functionality that typically requires such entry points. The presence of 0 unprotected entry points aligns with this, but without understanding the plugin's purpose, it's difficult to definitively assess if this is intentional or an oversight.

The most significant concern stems from the complete absence of nonce checks and capability checks. This suggests that any actions taken by the plugin, even if not directly exposed through apparent entry points, might be susceptible to CSRF attacks if they modify data or settings. The two external HTTP requests, while not inherently a vulnerability, warrant review to ensure they are made securely and do not expose sensitive information or introduce supply chain risks. The taint analysis showing zero flows with unsanitized paths is a positive indicator, suggesting no obvious command injection or path traversal vulnerabilities were found.

The vulnerability history is spotless, with zero known CVEs. This, combined with the positive findings in static analysis, paints a picture of a plugin that, at first glance, appears to be secure. However, the significant gaps in security checks (nonces, capabilities) and the unusual lack of identifiable attack surface require careful consideration. While the plugin has no recorded history of vulnerabilities, this is not a guarantee of future security, especially given the potential for undiscovered flaws related to the missing checks. In conclusion, the plugin demonstrates strengths in handling SQL and output escaping, but weaknesses in crucial authorization and anti-CSRF mechanisms are present and represent the primary areas of concern.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP requests without explicit security review
Vulnerabilities
None known

Paysenz Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Paysenz Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Paysenz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
28 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped28 total outputs
Attack Surface

Paysenz Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwoocommerce_payment_gatewayspaysenz.php:28
actionplugins_loadedpaysenz.php:34
actionwoocommerce_api_paysenz-payment-completepaysenz.php:71
Maintenance & Trust

Paysenz Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 10, 2019
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Paysenz Developer Profile

unlocklive

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paysenz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-paysenz-payment-gateway/assets/images/paysenz-logo.png

HTML / DOM Fingerprints

REST Endpoints
/wc-api/paysenz-payment-complete
FAQ

Frequently Asked Questions about Paysenz