ZionPe Payments Security & Risk Analysis

wordpress.org/plugins/zionpe-payments

Accept payments on WordPress & WooCommerce: credit/debit card, Google Pay, Apple Pay, and bank transfer. Sign up at ZionPe, connect your store—sec …

0 active installs v1.12.0 PHP 7.4+ WP 5.0+ Updated Feb 22, 2026
credit-cardpayment-gatewaypaymentsstripewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZionPe Payments Safe to Use in 2026?

Generally Safe

Score 100/100

ZionPe Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "zionpe-payments" plugin v1.12.0 exhibits a generally positive security posture, with several good practices observed. Notably, 100% of SQL queries utilize prepared statements and a high percentage of output is properly escaped, indicating a good understanding of fundamental web security. The plugin also demonstrates a reasonable number of nonce and capability checks, suggesting an effort to secure various functionalities.

However, there are specific areas of concern that warrant attention. The presence of two AJAX handlers without authentication checks introduces a significant attack surface. While taint analysis shows no critical or high-severity vulnerabilities in the analyzed flows, the lack of these checks on AJAX endpoints could allow for unauthorized actions if these handlers perform sensitive operations. The plugin also makes a notable number of external HTTP requests, which, without careful validation of the returned data, could potentially be a vector for certain types of attacks, although this is not explicitly flagged as a vulnerability in the provided data.

The plugin's vulnerability history is clean, with zero known CVEs. This is a strong positive indicator and suggests that, historically, the plugin has been relatively secure. However, this does not negate the risks identified in the static analysis. The conclusion is that "zionpe-payments" v1.12.0 has several strengths in its coding practices, particularly around database interactions and output escaping. Nevertheless, the two unprotected AJAX endpoints represent a clear and present risk that needs to be addressed to improve its overall security.

Key Concerns

  • AJAX handlers without auth checks
Vulnerabilities
None known

ZionPe Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZionPe Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
72 escaped
Nonce Checks
3
Capability Checks
7
File Operations
1
External Requests
7
Bundled Libraries
0

Output Escaping

96% escaped75 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
ajax_verify_connection (zionpe-payments.php:191)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

ZionPe Payments Attack Surface

Entry Points5
Unprotected2

AJAX Handlers 4

authwp_ajax_zionpe_get_redirect_dataincludes\class-zionpe-wc-gateway.php:74
noprivwp_ajax_zionpe_get_redirect_dataincludes\class-zionpe-wc-gateway.php:75
authwp_ajax_zionpe_verify_connectionzionpe-payments.php:70
authwp_ajax_zionpe_get_revenue_statszionpe-payments.php:114

Shortcodes 1

[zionpe_payment] zionpe-payments.php:89
WordPress Hooks 24
actionwp_enqueue_scriptsincludes\class-zionpe-wc-gateway.php:72
actionwoocommerce_api_zionpe_webhookincludes\class-zionpe-wc-gateway.php:73
actionwoocommerce_thankyouincludes\class-zionpe-wc-gateway.php:76
actionwp_footerincludes\class-zionpe-wc-gateway.php:80
actionadmin_menuzionpe-payments.php:67
actionadmin_initzionpe-payments.php:68
actionadmin_enqueue_scriptszionpe-payments.php:69
filterpre_set_site_transient_update_pluginszionpe-payments.php:74
filtersite_transient_update_pluginszionpe-payments.php:75
filterplugins_apizionpe-payments.php:76
actionadmin_initzionpe-payments.php:79
actionload-plugins.phpzionpe-payments.php:82
actionadmin_head-plugins.phpzionpe-payments.php:85
actionwp_enqueue_scriptszionpe-payments.php:88
actionplugins_loadedzionpe-payments.php:92
filterwoocommerce_payment_gatewayszionpe-payments.php:93
actionwoocommerce_blocks_loadedzionpe-payments.php:96
actionbefore_woocommerce_initzionpe-payments.php:99
filterplugin_row_metazionpe-payments.php:103
actionadmin_noticeszionpe-payments.php:106
actionadmin_initzionpe-payments.php:109
actionwp_dashboard_setupzionpe-payments.php:112
actionadmin_enqueue_scriptszionpe-payments.php:113
actionwoocommerce_blocks_payment_method_type_registrationzionpe-payments.php:1415
Maintenance & Trust

ZionPe Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version7.4
Downloads331

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZionPe Payments Developer Profile

zionpe

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZionPe Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zionpe-payments/assets/css/admin.css/wp-content/plugins/zionpe-payments/assets/js/admin.js/wp-content/plugins/zionpe-payments/assets/css/frontend.css/wp-content/plugins/zionpe-payments/assets/js/frontend.js/wp-content/plugins/zionpe-payments/assets/js/checkout.js/wp-content/plugins/zionpe-payments/assets/js/blocks.js/wp-content/plugins/zionpe-payments/assets/js/dashboard.js
Script Paths
/wp-content/plugins/zionpe-payments/assets/js/admin.js/wp-content/plugins/zionpe-payments/assets/js/frontend.js/wp-content/plugins/zionpe-payments/assets/js/checkout.js/wp-content/plugins/zionpe-payments/assets/js/blocks.js/wp-content/plugins/zionpe-payments/assets/js/dashboard.js
Version Parameters
zionpe-payments/assets/css/admin.css?ver=zionpe-payments/assets/js/admin.js?ver=zionpe-payments/assets/css/frontend.css?ver=zionpe-payments/assets/js/frontend.js?ver=zionpe-payments/assets/js/checkout.js?ver=zionpe-payments/assets/js/blocks.js?ver=zionpe-payments/assets/js/dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
zionpe-payment-formzionpe-checkout-formzionpe-gateway-settingszionpe-admin-wrapzionpe-noticezionpe-dashboard-widget
HTML Comments
<!-- ZionPe Payment Form --><!-- ZionPe Checkout Form --><!-- ZionPe Admin Settings --><!-- ZionPe Notice -->+1 more
Data Attributes
data-zionpe-payment-iddata-zionpe-amountdata-zionpe-currencydata-zionpe-api-keydata-zionpe-return-urldata-zionpe-merchant-id
JS Globals
zionpe_adminzionpe_frontendzionpe_checkoutzionpe_blocks
REST Endpoints
/wp-json/zionpe-payments/v1/verify-connection/wp-json/zionpe-payments/v1/revenue-stats
Shortcode Output
[zionpe_payment]
FAQ

Frequently Asked Questions about ZionPe Payments