
WP Weixin Pay Security & Risk Analysis
wordpress.org/plugins/wp-weixin-paySimple WeChat Pay integration for WordPress.
Is WP Weixin Pay Safe to Use in 2026?
Generally Safe
Score 85/100WP Weixin Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-weixin-pay" plugin version 1.3.15 exhibits a concerning security posture primarily due to its extensive unprotected attack surface. While the code demonstrates good practices in SQL query handling and output escaping, the presence of seven AJAX handlers without authentication checks represents a significant risk. This means that any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure. The taint analysis, while not revealing critical or high severity issues, did identify one flow with unsanitized paths, which could be a potential avenue for exploitation if combined with other vulnerabilities or misconfigurations.
The plugin's vulnerability history is currently clean, with no known CVEs. This is a positive indicator, suggesting that the developers have not historically introduced major security flaws. However, the lack of past vulnerabilities does not negate the immediate risks identified in the static analysis. The plugin's strengths lie in its secure handling of database interactions and output rendering, but these are overshadowed by the critical oversight of failing to implement proper authorization checks on its AJAX endpoints. Therefore, while the plugin has a good track record, the current version requires immediate attention to secure its entry points.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized paths (taint analysis)
- Missing capability checks
WP Weixin Pay Security Vulnerabilities
WP Weixin Pay Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Weixin Pay Attack Surface
AJAX Handlers 7
WordPress Hooks 28
Scheduled Events 1
Maintenance & Trust
WP Weixin Pay Maintenance & Trust
Maintenance Signals
Community Trust
WP Weixin Pay Alternatives
Checkout with Zelle on Woocommerce
wc-zelle
Receive Zelle payments on your website with WooCommerce + Zelle
Receive customer payments on Woocommerce
momo-venmo
Receive Venmo payments on your website with WooCommerce + Venmo
Payment gateway for WooCommerce – Woo WeChatPay
woo-wechatpay
WeChat Pay payment gateway for WooCommerce.
WeChat Payments for WooCommerce
wechat-payment-for-woo
WeChat Payments for WooCommerce is a Wordpress plugin that allows to accept payments at WooCommerce-powered online stores.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WP Weixin Pay Developer Profile
11 plugins · 8K total installs
How We Detect WP Weixin Pay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-weixin-pay/assets/css/wxpay-style.css/wp-content/plugins/wp-weixin-pay/assets/js/wxpay-script.js/wp-content/plugins/wp-weixin-pay/assets/js/wxpay-admin-script.js/wp-content/plugins/wp-weixin-pay/assets/js/wxpay-script.js/wp-content/plugins/wp-weixin-pay/assets/js/wxpay-admin-script.jswp-weixin-pay/assets/css/wxpay-style.css?ver=wp-weixin-pay/assets/js/wxpay-script.js?ver=wp-weixin-pay/assets/js/wxpay-admin-script.js?ver=HTML / DOM Fingerprints
wxpay-qr-code-containerwxpay-donate-button<!-- WeChat Pay QR Code --><!-- Donate Button -->data-wxpay-product-iddata-wxpay-amountdata-wxpay-descriptionwxpay_params/wp-json/wp-weixin-pay/v1/create-payment/wp-json/wp-weixin-pay/v1/check-payment[weixin_pay_qr][weixin_pay_donate]