
Payment Gateway Authorize.Net CIM for WooCommerce Security & Risk Analysis
wordpress.org/plugins/authnet-cim-for-wooAuthorize.Net CIM for WooCommerce allows merchants to accept credit cards with support for stored cardholder profiles, subscriptions, and pre-orders.
Is Payment Gateway Authorize.Net CIM for WooCommerce Safe to Use in 2026?
Use With Caution
Score 63/100Payment Gateway Authorize.Net CIM for WooCommerce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The authnet-cim-for-woo plugin v2.1.2 exhibits a mixed security posture. On the positive side, the static analysis shows excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. The plugin also correctly implements nonce checks for its two AJAX entry points and has no identified file operations or raw SQL queries. The absence of dangerous functions and taint analysis revealing no unsanitized paths further contribute to its good internal code quality.
However, the plugin's vulnerability history presents a significant concern. There is one known medium-severity CVE that remains unpatched. The common vulnerability type being 'Missing Authorization' in past issues suggests a recurring pattern that attackers could exploit. While current code analysis shows no immediate authorization flaws on entry points, the historical trend and the presence of an unpatched vulnerability are critical indicators of potential risk. The plugin also makes external HTTP requests, which could be a vector if not handled securely, although this is not explicitly flagged as a vulnerability in the static analysis.
In conclusion, authnet-cim-for-woo v2.1.2 benefits from strong internal coding practices, but the presence of an unpatched medium-severity CVE and a history of authorization issues significantly elevate its risk profile. Users should prioritize addressing the unpatched vulnerability to mitigate the most pressing security threat.
Key Concerns
- Unpatched CVE (medium severity)
- Vulnerability history of missing authorization
Payment Gateway Authorize.Net CIM for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Payment Gateway Authorize.Net CIM for WooCommerce <= 2.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Deletion
Payment Gateway Authorize.Net CIM for WooCommerce Code Analysis
Output Escaping
Payment Gateway Authorize.Net CIM for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 17
Maintenance & Trust
Payment Gateway Authorize.Net CIM for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Payment Gateway Authorize.Net CIM for WooCommerce Alternatives
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Authorize.Net/eProcessing Network Payment Gateway for WooCommerce
authorizenet-woocommerce-lightweight-addon
This plugin is an addon for WooCommerce to implement a payment gateway method for accepting Credit Cards Payments By merchants via Authorize.
eProcessing Network Payment Gateway for WooCommerce
epn-woocommerce-addon
This plugin is an addon for WooCommerce to implement a payment gateway method for accepting Credit Cards Payments By merchants via eProcessing Network …
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Payment Gateway Authorize.Net CIM for WooCommerce Developer Profile
4 plugins · 1K total installs
How We Detect Payment Gateway Authorize.Net CIM for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/authnet-cim-for-woo/assets/css/authnet-admin.css/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-admin.js/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-checkout.js/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-admin.js/wp-content/plugins/authnet-cim-for-woo/assets/js/authnet-checkout.jsauthnet-cim-for-woo/assets/css/authnet-admin.css?ver=authnet-cim-for-woo/assets/js/authnet-admin.js?ver=authnet-cim-for-woo/assets/js/authnet-checkout.js?ver=HTML / DOM Fingerprints
wc_cardpay_authnet_gateway_wrapCopyright 2016 Cardpay Solutions, Inc. (email : sales@cardpaysolutions.com)This program is free software: you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General License+3 moredata-authnet-customer-iddata-authnet-payment-iddata-authnet-tokenWC_Cardpay_Authnet_Checkout