
PromptPay Security & Risk Analysis
wordpress.org/plugins/wp-promptpayPromptPay integration for WordPress, contract creator if any
Is PromptPay Safe to Use in 2026?
Generally Safe
Score 85/100PromptPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-promptpay plugin v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and SQL queries without prepared statements are significant strengths. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of responsible development and maintenance.
However, there are notable areas for improvement. The lack of nonce checks and capability checks, especially with a shortcode present, represents a potential weakness. If the shortcode's functionality can be exploited, an attacker might be able to trigger it without proper authorization. Additionally, the 33% of outputs that are not properly escaped could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs.
In conclusion, while the plugin is free of known critical issues and demonstrates good coding practices in several areas, the identified weaknesses in authorization checks and output escaping warrant attention. Addressing these concerns would significantly enhance the plugin's overall security.
Key Concerns
- No nonce checks found
- No capability checks found
- Outputs not properly escaped (33%)
PromptPay Security Vulnerabilities
PromptPay Code Analysis
Output Escaping
PromptPay Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
PromptPay Maintenance & Trust
Maintenance Signals
Community Trust
PromptPay Alternatives
Razorpay Payment Links for WooCommerce
rzp-woocommerce
The easiest and most secure solution to collect payments with WooCommerce. Allow customers to securely pay via Razorpay (Credit/Debit Cards, NetBankin …
UPI QR Code Payment Gateway
upi-qr-code-payment-gateway
This Plugin enables WooCommerce shop owners to get direct and instant payments through UPI apps like GPay, PhonePe, Paytm or any banking UPI app.
sqrip.ch
sqrip-swiss-qr-invoice
sqrip – A comprehensive, flexible and clever WooCommerce finance tool for the most widely used payment method in Switzerland: the bank transfers.
Autopilot For UPI QR Code Payment Gateway for WooCommerce
autopilot-for-upi-qr-code-payment-gateway
This plugin automates the payment verification process for WooCommerce orders made through the UPI QR Code Payment Gateway for WooCommerce, facilitati …
Negpay qrcode Payment Gateway
integration-qr-code-payment-gateway
This Plugin enables WooCommerce shopowners to instant payments through bank apps like banking app to save payment gateway charges in Mongolia.
PromptPay Developer Profile
6 plugins · 2K total installs
How We Detect PromptPay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-promptpay/js/promptpay.jswp-promptpay/js/promptpay.js?ver=HTML / DOM Fingerprints
ppy-card<!-- hack --><!-- @todo refactor --><!-- ================================================================ WooCommerce --><!-- @todo refactor -->+8 moredata-promptpay-iddata-amountdata-show-promptpay-logodata-show-promptpay-iddata-account-namedata-shop-name+1 more<div class="ppy-card"