ExpressPay Woocommerce Payment Gateway Security & Risk Analysis

wordpress.org/plugins/woocommerce-expresspay-payment-gateway

Expresspay Woocommerce Payment Gateway allows you to accept payment on your Woocommerce store via Visa Ghana, Visacard, MasterCard, American Express, …

80 active installs v2.0.0 PHP + WP 3.0.1+ Updated Jan 15, 2016
mastercardpaymentpayment-gatewayvisa-cardswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ExpressPay Woocommerce Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

ExpressPay Woocommerce Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The WooCommerce ExpressPay Payment Gateway plugin v2.0.0 presents a mixed security profile. On the positive side, the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the plugin demonstrates good practices by using prepared statements exclusively for SQL queries and has no known vulnerabilities (CVEs) on record, suggesting a history of responsible development and patching.

However, significant concerns arise from the complete lack of output escaping, with 100% of identified outputs being unescaped. This is a critical weakness that could lead to Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is reflected in the output. Additionally, the absence of nonce checks and capability checks on any entry points, coupled with no taint analysis data, means that potential vulnerabilities in these areas cannot be ruled out and may exist undetected. The plugin also makes external HTTP requests without clear sanitization or authentication checks, which could be exploited for various attacks depending on the nature of these requests.

In conclusion, while the plugin's attack surface and vulnerability history are reassuring, the critical lack of output escaping and the absence of essential security checks like nonces and capability checks represent substantial risks. The plugin would benefit greatly from implementing robust output sanitization and incorporating proper authentication and authorization mechanisms to mitigate potential security threats.

Key Concerns

  • 100% unescaped output
  • 0 Nonce checks
  • 0 Capability checks
  • External HTTP requests without clear auth/sanitization
Vulnerabilities
None known

ExpressPay Woocommerce Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ExpressPay Woocommerce Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

ExpressPay Woocommerce Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedexpresspay-woocommere-gateway.php:19
actionwoocommerce_update_options_payment_gatewaysexpresspay-woocommere-gateway.php:70
filterwoocommerce_currenciesexpresspay-woocommere-gateway.php:407
filterwoocommerce_currency_symbolexpresspay-woocommere-gateway.php:408
filterwoocommerce_payment_gatewaysexpresspay-woocommere-gateway.php:411
Maintenance & Trust

ExpressPay Woocommerce Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 15, 2016
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

ExpressPay Woocommerce Payment Gateway Developer Profile

Akin Delu

3 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ExpressPay Woocommerce Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-expresspay-payment-gateway/assets/images/logo.png

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ExpressPay Woocommerce Payment Gateway