Bank mellat EDD gateway Security & Risk Analysis

wordpress.org/plugins/bank-mellat-edd-gateway

This plugin will add Bank Mellat and Shaparak Electronic Network gateway to EDD plugin + sms افزونه بانک ملت برای افزونه فروش فایل EDD

20 active installs v4.2 PHP + WP 3.0+ Updated Apr 3, 2018
bank-mellateasy-digital-downloadsedd-gateways
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bank mellat EDD gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Bank mellat EDD gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "bank-mellat-edd-gateway" v4.2 plugin exhibits a concerning security posture despite a lack of publicly disclosed vulnerabilities. The static analysis reveals a complete absence of protective measures such as nonce checks and capability checks, indicating a potential for unauthorized actions if any entry points were exposed. Furthermore, the fact that 0% of the 31 identified outputs are properly escaped is a significant red flag. This means that any data outputted by the plugin, which could originate from user input or other sources, is not being sanitized, opening the door to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also identified flows with unsanitized paths, although thankfully without critical or high severity, this still points to areas where data is not being handled securely. The lack of any recorded vulnerabilities in its history might suggest low exposure or a lack of targeted attacks, but it does not guarantee inherent security given the weaknesses identified in the code itself. The plugin demonstrates strengths in its use of prepared statements for SQL queries and avoiding file operations or external HTTP requests. However, the pervasive lack of output escaping and the absence of essential security checks like nonces and capability checks present a significant risk.

Key Concerns

  • Output escaping: 0% properly escaped
  • Capability checks: 0
  • Nonce checks: 0
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Bank mellat EDD gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bank mellat EDD gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped31 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bpm_verify (Mellat_for_EDD.php:141)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bank mellat EDD gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filteredd_rial_currency_filter_afterMellat_for_EDD.php:27
filteredd_payment_gatewaysMellat_for_EDD.php:33
filteredd_Mellat_cc_formMellat_for_EDD.php:38
actionedd_gateway_MellatMellat_for_EDD.php:139
actioninitMellat_for_EDD.php:277
filteredd_settings_gatewaysMellat_for_EDD.php:311
actionadmin_menumenu_setup.php:3
Maintenance & Trust

Bank mellat EDD gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 3, 2018
PHP min version
Downloads14K

Community Trust

Rating88/100
Number of ratings7
Active installs20
Developer Profile

Bank mellat EDD gateway Developer Profile

Arash Heidari

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bank mellat EDD gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bank-mellat-edd-gateway/inc/css/style.css/wp-content/plugins/bank-mellat-edd-gateway/inc/js/script.js
Script Paths
/wp-content/plugins/bank-mellat-edd-gateway/inc/js/script.js
Version Parameters
/wp-content/plugins/bank-mellat-edd-gateway/inc/css/style.css?ver=/wp-content/plugins/bank-mellat-edd-gateway/inc/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
MellatPay
HTML Comments
if ($PayResult[0] == "0") {// Successfull Pay Request//************END of PAY REQUEST***************//VERIFY REQUEST+6 more
Data Attributes
name="MellatPay"type="hidden"name="RefId"
JS Globals
MellatPay
FAQ

Frequently Asked Questions about Bank mellat EDD gateway