Autify Digital Ltd Lloyds Cardnet Gateway Security & Risk Analysis

wordpress.org/plugins/autifydigital-lloyds-cardnet

A payment gateway integration between WooCommerce and Lloyds Cardnet Payments.

80 active installs v3.0.12 PHP 7.4+ WP 6.0+ Updated Mar 24, 2026
paymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Autify Digital Ltd Lloyds Cardnet Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Autify Digital Ltd Lloyds Cardnet Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The autifydigital-lloyds-cardnet plugin version 3.0.12 exhibits a mixed security posture. On the positive side, it demonstrates good practices in database interactions, with 100% of SQL queries utilizing prepared statements, and a very high rate of output escaping. The absence of known CVEs and a clean vulnerability history is also a strong indicator of past security diligence. However, significant concerns arise from the attack surface analysis. A notable portion of AJAX handlers (12 out of 27) lack authentication checks, presenting a potential entry point for unauthorized actions if these handlers perform sensitive operations. Furthermore, the taint analysis reveals a high number of flows with unsanitized paths, with 14 identified as high severity. This suggests that user-supplied data may not be adequately validated or sanitized before being used in sensitive operations, potentially leading to vulnerabilities like cross-site scripting (XSS) or server-side request forgery (SSRF) if these flows are exposed via the unprotected AJAX endpoints.

Key Concerns

  • High number of unprotected AJAX handlers
  • High severity taint flows with unsanitized paths
Vulnerabilities
None known

Autify Digital Ltd Lloyds Cardnet Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Autify Digital Ltd Lloyds Cardnet Gateway Release Timeline

v3.0.12Current
v3.0.11
v3.0.10
v3.0.9
v3.0.8
v3.0.7
v3.0.6
v3.0.5
Code Analysis
Analyzed Apr 16, 2026

Autify Digital Ltd Lloyds Cardnet Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
51 prepared
Unescaped Output
9
661 escaped
Nonce Checks
11
Capability Checks
25
File Operations
3
External Requests
7
Bundled Libraries
0

SQL Query Safety

100% prepared51 total queries

Output Escaping

99% escaped670 total outputs
Data Flows · Security
20 unsanitized

Data Flow Analysis

22 flows20 with unsanitized paths
do_export_csv (admin/lloyds-cardnet-report/lloyds_cardnet_reports.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
12 unprotected

Autify Digital Ltd Lloyds Cardnet Gateway Attack Surface

Entry Points28
Unprotected12

AJAX Handlers 27

authwp_ajax_autify_lloyds_save_shipping_descriptionadmin/class-autify-lloyds-wallet-shipping-settings.php:45
authwp_ajax_autify_lloyds_delete_shipping_descriptionadmin/class-autify-lloyds-wallet-shipping-settings.php:46
authwp_ajax_autify_lloyds_cardnet_export_csvautifydigital-lloyds-cardnet.php:55
authwp_ajax_autify_lloyds_hpp_set_save_card_prefincludes/class-autify-lloyds-cardnet-gateway-blocks-support.php:29
noprivwp_ajax_autify_lloyds_hpp_set_save_card_prefincludes/class-autify-lloyds-cardnet-gateway-blocks-support.php:30
authwp_ajax_autify_lloyds_paymentjs_set_save_card_prefincludes/class-autify-lloyds-cardnet-paymentjs-gateway.php:145
noprivwp_ajax_autify_lloyds_paymentjs_set_save_card_prefincludes/class-autify-lloyds-cardnet-paymentjs-gateway.php:146
authwp_ajax_autify_lloyds_activate_licenseincludes/class-autify-lloyds-license-manager.php:49
authwp_ajax_autify_lloyds_generate_licenseincludes/class-autify-lloyds-license-manager.php:50
authwp_ajax_autify_lloyds_tracking_consentincludes/class-autify-lloyds-license-manager.php:51
authwp_ajax_autify_lloyds_dismiss_license_noticeincludes/class-autify-lloyds-license-manager.php:52
authwp_ajax_autify_lloyds_paymentjs_authorizeSessionincludes/controller/class-autify-lloyds-paymentjs-authorize-session.php:24
noprivwp_ajax_autify_lloyds_paymentjs_authorizeSessionincludes/controller/class-autify-lloyds-paymentjs-authorize-session.php:25
noprivwp_ajax_autify_lloyds_add_to_cartincludes/controller/wallet/class-autify-lloyds-add-to-cart.php:11
authwp_ajax_autify_lloyds_add_to_cartincludes/controller/wallet/class-autify-lloyds-add-to-cart.php:12
authwp_ajax_autify_lloyds_check_cart_subscriptionincludes/controller/wallet/class-autify-lloyds-check-cart-subscription.php:19
noprivwp_ajax_autify_lloyds_check_cart_subscriptionincludes/controller/wallet/class-autify-lloyds-check-cart-subscription.php:20
noprivwp_ajax_autify_lloyds_process_apple_pay_orderincludes/controller/wallet/class-autify-lloyds-process-apple-pay-order.php:13
authwp_ajax_autify_lloyds_process_apple_pay_orderincludes/controller/wallet/class-autify-lloyds-process-apple-pay-order.php:14
noprivwp_ajax_autify_lloyds_process_google_pay_orderincludes/controller/wallet/class-autify-lloyds-process-google-pay-order.php:13
authwp_ajax_autify_lloyds_process_google_pay_orderincludes/controller/wallet/class-autify-lloyds-process-google-pay-order.php:14
noprivwp_ajax_autify_lloyds_shipping_methodsincludes/controller/wallet/class-autify-lloyds-shipping-methods.php:11
authwp_ajax_autify_lloyds_shipping_methodsincludes/controller/wallet/class-autify-lloyds-shipping-methods.php:12
noprivwp_ajax_autify_lloyds_validate_apple_pay_merchantincludes/controller/wallet/class-autify-lloyds-validate-apple-pay-merchant.php:45
authwp_ajax_autify_lloyds_validate_apple_pay_merchantincludes/controller/wallet/class-autify-lloyds-validate-apple-pay-merchant.php:46
noprivwp_ajax_autify_lloyds_validate_shipping_addressincludes/controller/wallet/class-autify-lloyds-validate-shipping-address.php:10
authwp_ajax_autify_lloyds_validate_shipping_addressincludes/controller/wallet/class-autify-lloyds-validate-shipping-address.php:11

Shortcodes 1

[autify_lloyds_error_gateway] includes/class-autify-lloyds-cardnet-gateway-function.php:146
WordPress Hooks 70
actionadmin_initadmin/class-autify-lloyds-cardnet-admin-function.php:47
actionadmin_menuadmin/class-autify-lloyds-cardnet-admin-function.php:49
actionadd_meta_boxesadmin/class-autify-lloyds-cardnet-admin-function.php:52
actionadmin_enqueue_scriptsadmin/class-autify-lloyds-cardnet-admin-function.php:54
filtermanage_edit-shop_order_columnsadmin/class-autify-lloyds-cardnet-admin-function.php:65
actionmanage_shop_order_posts_custom_columnadmin/class-autify-lloyds-cardnet-admin-function.php:66
filterwoocommerce_shop_order_list_table_columnsadmin/class-autify-lloyds-cardnet-admin-function.php:69
actionwoocommerce_shop_order_list_table_custom_columnadmin/class-autify-lloyds-cardnet-admin-function.php:70
filtermanage_edit-shop_order_sortable_columnsadmin/class-autify-lloyds-cardnet-admin-function.php:73
filterwoocommerce_shop_order_list_table_sortable_columnsadmin/class-autify-lloyds-cardnet-admin-function.php:74
actionadmin_enqueue_scriptsadmin/class-autify-lloyds-cardnet-admin-function.php:77
actionadmin_menuadmin/class-autify-lloyds-wallet-shipping-settings.php:43
actionadmin_initadmin/class-autify-lloyds-wallet-shipping-settings.php:44
actionadmin_enqueue_scriptsadmin/class-autify-lloyds-wallet-shipping-settings.php:47
actioninitautifydigital-lloyds-cardnet.php:83
actionplugins_loadedautifydigital-lloyds-cardnet.php:128
actionbefore_woocommerce_initautifydigital-lloyds-cardnet.php:140
actionbefore_woocommerce_initincludes/class-autify-lloyds-cardnet-gateway-function.php:134
filterwoocommerce_payment_gatewaysincludes/class-autify-lloyds-cardnet-gateway-function.php:136
filterwoocommerce_available_payment_gatewaysincludes/class-autify-lloyds-cardnet-gateway-function.php:138
filterwoocommerce_available_payment_gatewaysincludes/class-autify-lloyds-cardnet-gateway-function.php:140
actionwp_enqueue_scriptsincludes/class-autify-lloyds-cardnet-gateway-function.php:142
actionwoocommerce_before_cartincludes/class-autify-lloyds-cardnet-gateway-function.php:144
actionwoocommerce_blocks_loadedincludes/class-autify-lloyds-cardnet-gateway-function.php:148
actionwoocommerce_thankyouincludes/class-autify-lloyds-cardnet-gateway-function.php:150
actionwpincludes/class-autify-lloyds-cardnet-gateway-function.php:152
actionwoocommerce_before_checkout_formincludes/class-autify-lloyds-cardnet-gateway-function.php:154
actionwoocommerce_pay_order_before_submitincludes/class-autify-lloyds-cardnet-gateway-function.php:156
filteruser_has_capincludes/class-autify-lloyds-cardnet-gateway-function.php:158
filterwoocommerce_order_received_verify_known_shoppersincludes/class-autify-lloyds-cardnet-gateway-function.php:160
actionwoocommerce_pay_order_before_paymentincludes/class-autify-lloyds-cardnet-gateway-function.php:163
actionwoocommerce_before_checkout_formincludes/class-autify-lloyds-cardnet-gateway-function.php:164
filterwoocommerce_payment_methods_list_itemincludes/class-autify-lloyds-cardnet-gateway-function.php:167
filterallowed_redirect_hostsincludes/class-autify-lloyds-cardnet-gateway-function.php:170
actionwoocommerce_blocks_payment_method_type_registrationincludes/class-autify-lloyds-cardnet-gateway-function.php:289
actionadmin_enqueue_scriptsincludes/class-autify-lloyds-cardnet-paymentjs-gateway.php:134
filterquery_varsincludes/class-autify-lloyds-cardnet-paymentjs-gateway.php:136
actionadmin_enqueue_scriptsincludes/class-autify-lloyds-cardnet-redirect-payment.php:147
actionadmin_noticesincludes/class-autify-lloyds-license-manager.php:45
actionadmin_noticesincludes/class-autify-lloyds-license-manager.php:46
actionadmin_initincludes/class-autify-lloyds-license-manager.php:47
actionadmin_menuincludes/class-autify-lloyds-license-manager.php:48
actionadmin_enqueue_scriptsincludes/class-autify-lloyds-license-manager.php:53
actioninitincludes/class-autify-lloyds-license-manager.php:56
actionwoocommerce_api_lloyds-checkout-webhookincludes/controller/checkout-solution/class-autify-lloyds-cardnet-checkout-webhook.php:40
actionwoocommerce_api_lloyds-checkout-failureincludes/controller/checkout-solution/class-autify-lloyds-cardnet-failure.php:45
actionwoocommerce_api_lloyds-checkout-successincludes/controller/checkout-solution/class-autify-lloyds-cardnet-success.php:49
actionwoocommerce_api_lloyds-3dsecure-iframemethodincludes/controller/class-autify-lloyds-3dsecure-iframemethod.php:23
actionwoocommerce_api_lloyds-3dsecure-processpaymentincludes/controller/class-autify-lloyds-3dsecure-processpayment.php:22
actionwoocommerce_api_lloyds-method-notification-urlincludes/controller/class-autify-lloyds-method-notification-url.php:22
actionwoocommerce_api_woo-lloyds-order-confirmationincludes/controller/class-autify-lloyds-order-confirmation.php:22
actionwoocommerce_api_lloyds-paymentjs-statusincludes/controller/class-autify-lloyds-paymentjs-status.php:23
actionwoocommerce_api_lloyds-paymentjs-webhookincludes/controller/class-autify-lloyds-paymentjs-webhook.php:23
actionwoocommerce_api_lloyds-process-paymentincludes/controller/class-autify-lloyds-process-payment.php:23
actionwoocommerce_api_lloyds-transaction-notification-urlincludes/controller/class-autify-lloyds-transaction-notification-url.php:23
actionwoocommerce_api_woo-lloyds-webhookincludes/controller/class-autify-lloyds-webhook.php:23
filterhttp_api_curlincludes/controller/wallet/class-autify-lloyds-validate-apple-pay-merchant.php:107
filtercron_schedulesincludes/cron/class-autify-lloyds-cardnet-unpaid-orders-cron.php:55
actioninitincludes/cron/class-autify-lloyds-cardnet-unpaid-orders-cron.php:58
actionautify_lloyds_cardnet_cancel_unpaid_ordersincludes/cron/class-autify-lloyds-cardnet-unpaid-orders-cron.php:61
actionwoocommerce_proceed_to_checkoutincludes/wallet/class-autify-lloyds-cardnet-applepay.php:21
actionwoocommerce_after_add_to_cart_formincludes/wallet/class-autify-lloyds-cardnet-applepay.php:22
actionwoocommerce_before_checkout_formincludes/wallet/class-autify-lloyds-cardnet-applepay.php:23
actionbefore_woocommerce_payincludes/wallet/class-autify-lloyds-cardnet-applepay.php:24
actionwp_enqueue_scriptsincludes/wallet/class-autify-lloyds-cardnet-applepay.php:25
actionwoocommerce_proceed_to_checkoutincludes/wallet/class-autify-lloyds-cardnet-googlepay.php:21
actionwoocommerce_after_add_to_cart_formincludes/wallet/class-autify-lloyds-cardnet-googlepay.php:22
actionwoocommerce_before_checkout_formincludes/wallet/class-autify-lloyds-cardnet-googlepay.php:23
actionbefore_woocommerce_payincludes/wallet/class-autify-lloyds-cardnet-googlepay.php:24
actionwp_enqueue_scriptsincludes/wallet/class-autify-lloyds-cardnet-googlepay.php:25

Scheduled Events 1

autify_lloyds_cardnet_cancel_unpaid_orders
Maintenance & Trust

Autify Digital Ltd Lloyds Cardnet Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 24, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Autify Digital Ltd Lloyds Cardnet Gateway Developer Profile

Autify Digital Ltd

2 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Autify Digital Ltd Lloyds Cardnet Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/autifydigital-lloyds-cardnet/admin/lloyds-cardnet-report/css/lloyds-cardnet-admin.css/wp-content/plugins/autifydigital-lloyds-cardnet/admin/lloyds-cardnet-report/js/lloyds-cardnet-admin.js/wp-content/plugins/autifydigital-lloyds-cardnet/assets/css/autify-lloyds-cardnet.css/wp-content/plugins/autifydigital-lloyds-cardnet/assets/js/autify-lloyds-cardnet.js
Script Paths
/wp-content/plugins/autifydigital-lloyds-cardnet/admin/lloyds-cardnet-report/js/lloyds-cardnet-admin.js/wp-content/plugins/autifydigital-lloyds-cardnet/assets/js/autify-lloyds-cardnet.js
Version Parameters
autifydigital-lloyds-cardnet/assets/css/autify-lloyds-cardnet.css?ver=autifydigital-lloyds-cardnet/assets/js/autify-lloyds-cardnet.js?ver=

HTML / DOM Fingerprints

CSS Classes
autify_lloyds_cardnet_report_wrapperautify_lloyds_cardnet_transaction_report_tableautify_lloyds_cardnet_transaction_details
HTML Comments
<!-- Autify Digital Ltd Lloyds Cardnet Gateway --><!-- Copyright (c) 2020-2026 Autify Digital Ltd. --><!-- Copyright (c) 2020-2025 Autify Digital Ltd. --><!-- Check and add missing database columns on admin load -->+3 more
Data Attributes
data-transaction-iddata-order-iddata-payment-status
JS Globals
autify_lloyds_cardnet_ajax_object
FAQ

Frequently Asked Questions about Autify Digital Ltd Lloyds Cardnet Gateway