
Pay with PAYUNi Security & Risk Analysis
wordpress.org/plugins/wpbr-payuni-paymentAccept payments via PAYUNi(統一金流) payment for your WooCommerce store.
Is Pay with PAYUNi Safe to Use in 2026?
Generally Safe
Score 100/100Pay with PAYUNi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpbr-payuni-payment" plugin version 1.8.1 exhibits a generally strong security posture based on the provided static analysis. It has a limited attack surface with only two AJAX entry points, and importantly, these appear to be protected by nonce checks. The absence of critical or high-severity taint flows, dangerous functions, and raw SQL queries is a significant positive. Furthermore, the plugin has no recorded vulnerability history, which suggests a commitment to security or a lack of past exploitable flaws.
However, there are areas for improvement. The plugin's capability checks are absent, which means that even though nonces are present, any user with access to the front-end could potentially trigger the AJAX actions, assuming these actions themselves don't have internal capability checks. While the majority of output is properly escaped, a percentage of it is not, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controllable or originates from an untrusted source. The external HTTP requests, while not inherently risky without further context, represent a potential avenue for supply chain attacks or information disclosure if the endpoints are compromised or malicious.
In conclusion, "wpbr-payuni-payment" v1.8.1 is relatively secure, with its main strengths being its small attack surface and lack of historical vulnerabilities. The key areas of concern are the missing capability checks on its AJAX handlers and the presence of unescaped output. Addressing these would further harden the plugin against potential attacks.
Key Concerns
- Missing capability checks on AJAX handlers
- Unescaped output detected
Pay with PAYUNi Security Vulnerabilities
Pay with PAYUNi Code Analysis
SQL Query Safety
Output Escaping
Pay with PAYUNi Attack Surface
AJAX Handlers 2
WordPress Hooks 20
Maintenance & Trust
Pay with PAYUNi Maintenance & Trust
Maintenance Signals
Community Trust
Pay with PAYUNi Alternatives
ccatpay Payment for WooCommerce
ccat-for-woocommerce
為您的 WooCommerce 網站添加 黑貓Pay 金流支付方式。
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pay with PAYUNi Developer Profile
2 plugins · 1K total installs
How We Detect Pay with PAYUNi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpbr-payuni-payment/assets/css/payuni-checkout.css/wp-content/plugins/wpbr-payuni-payment/assets/js/payuni-checkout.js/wp-content/plugins/wpbr-payuni-payment/assets/js/payuni-admin.js/wp-content/plugins/wpbr-payuni-payment/assets/js/payuni-checkout.js/wp-content/plugins/wpbr-payuni-payment/assets/js/payuni-admin.jswpbr-payuni-payment/assets/css/payuni-checkout.css?ver=wpbr-payuni-payment/assets/js/payuni-checkout.js?ver=wpbr-payuni-payment/assets/js/payuni-admin.js?ver=HTML / DOM Fingerprints
payuni-payment-formpayuni-payment-methoddata-payuni-checkoutpayuni_checkout_params