YD Culqi gateway for AliDropship Security & Risk Analysis

wordpress.org/plugins/yd-culqi-gateway-for-alidropship

YD Culqi payment gateway for AliDropship provides an easy way to take credit card payments on your online store using Culqi.

10 active installs v2.0 PHP 7.1+ WP + Updated Apr 4, 2022
alidropshipaliexpress-dropshippingculqi-payment-gatewaydropshipping-storepayment-gateway
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YD Culqi gateway for AliDropship Safe to Use in 2026?

Generally Safe

Score 85/100

YD Culqi gateway for AliDropship has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The yd-culqi-gateway-for-alidropship plugin v2.0 exhibits a concerning security posture due to its unprotected entry points. While the plugin shows positive signs like using prepared statements for all SQL queries and a lack of dangerous functions, its significant vulnerability lies in its AJAX handlers. Two AJAX handlers are present, and critically, neither has authentication checks. This means any unauthenticated user can potentially trigger these handlers, presenting a significant attack surface. The absence of taint analysis results and vulnerability history doesn't necessarily indicate perfect security, but rather a lack of reported issues or analysis conducted. The plugin's 25% proper output escaping is also a weakness, suggesting potential for cross-site scripting (XSS) vulnerabilities in the unescaped outputs.

Key Concerns

  • AJAX handlers without authentication
  • Low percentage of properly escaped output
  • Lack of nonce checks on AJAX handlers
Vulnerabilities
None known

YD Culqi gateway for AliDropship Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YD Culqi gateway for AliDropship Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped8 total outputs
Attack Surface
2 unprotected

YD Culqi gateway for AliDropship Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_cg_action_gatewaycore\init.php:337
noprivwp_ajax_cg_action_gatewaycore\init.php:338
WordPress Hooks 6
filtercg_currenciescore\init.php:53
filterads_list_gateway_settingscore\init.php:129
filterads_list_gateway_namescore\init.php:143
filterads_gateways_pathcore\init.php:157
actionads_gateway_culqicore\init.php:311
actioninityd-culqi-gateway-for-alidropship.php:24
Maintenance & Trust

YD Culqi gateway for AliDropship Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 4, 2022
PHP min version7.1
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

YD Culqi gateway for AliDropship Developer Profile

axeleus

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YD Culqi gateway for AliDropship

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/css/common.css/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/js/common.js/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/css/frontend.css/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/js/frontend.js/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/js/backend.js
Script Paths
/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/js/common.js/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/js/frontend.js/wp-content/plugins/yd-culqi-gateway-for-alidropship/public/js/backend.js
Version Parameters
yd-culqi-gateway-for-alidropship/public/css/common.css?ver=yd-culqi-gateway-for-alidropship/public/js/common.js?ver=yd-culqi-gateway-for-alidropship/public/css/frontend.css?ver=yd-culqi-gateway-for-alidropship/public/js/frontend.js?ver=yd-culqi-gateway-for-alidropship/public/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
culqi-gateway-form
Data Attributes
data-culqi-amountdata-culqi-descriptiondata-culqi-button-textdata-culqi-titledata-culqi-currencydata-culqi-country+5 more
JS Globals
Culqi
Shortcode Output
[culqi_gateway]
FAQ

Frequently Asked Questions about YD Culqi gateway for AliDropship