
zipMoney(Zip Co) Payments Plugin for WooCommerce Security & Risk Analysis
wordpress.org/plugins/zipmoney-payments-woocommerceSell more online & in-store with Zip.
Is zipMoney(Zip Co) Payments Plugin for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100zipMoney(Zip Co) Payments Plugin for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zipmoney-payments-woocommerce plugin, version 2.3.30, exhibits a generally strong security posture regarding its attack surface. The analysis shows zero entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks. This significantly limits the potential for unauthorized access or manipulation through common WordPress vectors.
However, the static analysis reveals several areas for concern. Notably, all three detected SQL queries are not using prepared statements, indicating a significant risk of SQL injection vulnerabilities. Additionally, while a majority of output is properly escaped, 27% of outputs are not, potentially exposing the site to cross-site scripting (XSS) attacks. The presence of unsanitized paths in taint analysis flows, although not flagged as critical or high severity, warrants attention as it suggests potential for path traversal or file inclusion issues. The plugin also makes an external HTTP request without explicit details on its security implications.
Fortunately, the plugin has no recorded vulnerability history, with zero known CVEs. This suggests a history of responsible development or a lack of past security flaws being publicly disclosed. Despite the positive history, the identified code signals, particularly the raw SQL queries and unescaped outputs, present immediate risks that should be addressed to maintain a secure environment.
Key Concerns
- Raw SQL queries detected
- Unescaped output detected
- Taint flows with unsanitized paths
- External HTTP request
- Missing Nonce checks
- Missing Capability checks
zipMoney(Zip Co) Payments Plugin for WooCommerce Security Vulnerabilities
zipMoney(Zip Co) Payments Plugin for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
zipMoney(Zip Co) Payments Plugin for WooCommerce Attack Surface
WordPress Hooks 32
Maintenance & Trust
zipMoney(Zip Co) Payments Plugin for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
zipMoney(Zip Co) Payments Plugin for WooCommerce Alternatives
No alternatives data available yet.
zipMoney(Zip Co) Payments Plugin for WooCommerce Developer Profile
1 plugin · 2K total installs
How We Detect zipMoney(Zip Co) Payments Plugin for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zipmoney-payments-woocommerce/assets/css/zipmoney.css/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney-widget.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney-checkout.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney-express.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney-widget.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney-checkout.js/wp-content/plugins/zipmoney-payments-woocommerce/assets/js/zipmoney-express.jszipmoney-payments-woocommerce/assets/css/zipmoney.css?ver=zipmoney-payments-woocommerce/assets/js/zipmoney.js?ver=zipmoney-payments-woocommerce/assets/js/zipmoney-widget.js?ver=zipmoney-payments-woocommerce/assets/js/zipmoney-checkout.js?ver=zipmoney-payments-woocommerce/assets/js/zipmoney-express.js?ver=HTML / DOM Fingerprints
zipmoney-widgetzip-widgetzipmoney-express-checkout-buttonzip-express-checkout-button<!-- Zip money Widget --><!-- Zipmoney Payment Gateway Widget --><!-- Zip money notification section on checkout page --><!-- Zipmoney Payment Gateway Widget Footer -->+1 moredata-zipmoney-order-iddata-zipmoney-payment-urldata-zipmoney-public-keydata-zipmoney-is-iframe-flowdata-zipmoney-merchant-idzipmoneyConfigzipWidgetzipmoney_express_checkout/wp-json/zipmoney/v1/payment/create/wp-json/zipmoney/v1/payment/update/wp-json/zipmoney/v1/payment/cancel