Quikly Payment Gateway Security & Risk Analysis

wordpress.org/plugins/woo-xchange-payments

This plugin integrates Woocommerce with Quikly Payment Facilitator button, which you can use as a Payment gateway for all major credit cards and even …

10 active installs v3 PHP 5.6+ WP 6.0+ Updated Aug 22, 2024
productswoocommerce-payments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quikly Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Quikly Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'woo-xchange-payments' v3 plugin presents a significant security risk primarily due to its unprotected AJAX handlers. With 4 AJAX handlers identified and all of them lacking authentication checks, an unauthenticated attacker could potentially trigger these functions and compromise the site's integrity. The absence of capability checks and nonce verification further exacerbates this risk, leaving these entry points vulnerable to various attacks like unauthorized actions or data manipulation.

While the plugin demonstrates good practices in SQL query handling (100% prepared statements) and avoids dangerous functions, file operations, and external HTTP requests, these strengths are overshadowed by the critical flaw in its AJAX endpoint security. The low percentage of properly escaped output (5%) is also a concern, indicating a potential for cross-site scripting (XSS) vulnerabilities, though the absence of taint analysis and a history of vulnerabilities makes the exact impact difficult to quantify. The lack of any recorded vulnerability history is positive, but it should not breed complacency, especially given the current unprotected attack surface.

In conclusion, the plugin has a weak security posture due to unprotected AJAX endpoints and insufficient output escaping. Despite good practices in other areas, the identified risks warrant immediate attention to secure these entry points and improve output sanitization. The absence of historical vulnerabilities is a mitigating factor, but the present code analysis reveals critical weaknesses.

Key Concerns

  • Unprotected AJAX handlers without auth checks
  • Low percentage of properly escaped output
  • Missing nonce checks on AJAX handlers
  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Quikly Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quikly Payment Gateway Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Quikly Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped20 total outputs
Attack Surface
4 unprotected

Quikly Payment Gateway Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_procesar_pago_exitosoxchange.php:130
noprivwp_ajax_procesar_pago_exitosoxchange.php:131
authwp_ajax_procesar_pago_fallidoxchange.php:170
noprivwp_ajax_procesar_pago_fallidoxchange.php:171
WordPress Hooks 6
actionwp_enqueue_scriptshelpers.php:162
actionwp_headhelpers.php:163
actionwoocommerce_after_shipping_ratehelpers.php:164
actionwp_footerxchange.php:84
filterwoocommerce_payment_gatewaysxchange.php:177
actionplugins_loadedxchange.php:187
Maintenance & Trust

Quikly Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 22, 2024
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Quikly Payment Gateway Developer Profile

Quikly

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quikly Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

JS Globals
window.addEventListener('message'
FAQ

Frequently Asked Questions about Quikly Payment Gateway