Bank Melli EDD gateway Security & Risk Analysis

wordpress.org/plugins/bank-melli-edd-gateway

This plugin will add Bank Melli Iran and Shaparak Electronic Network gateway to EDD plugin.

40 active installs v1.5.2 PHP + WP 3.0+ Updated Aug 13, 2018
bank-mellieasy-digital-downloadsedd-gatewaysmelli%d8%af%d8%b1%da%af%d8%a7%d9%87-%d8%a8%d8%a7%d9%86%da%a9-%d9%85%d9%84%db%8c
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bank Melli EDD gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Bank Melli EDD gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "bank-melli-edd-gateway" plugin v1.5.2 exhibits a generally positive security posture based on the provided static analysis. The absence of identifiable attack surface vectors like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces its exposure to common web vulnerabilities. Furthermore, the code signals indicate a strong adherence to secure coding practices, with no dangerous functions, file operations, or external HTTP requests detected. The complete utilization of prepared statements for SQL queries is a major strength, mitigating the risk of SQL injection. However, a notable concern is the relatively low percentage (38%) of properly escaped outputs, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The lack of recorded vulnerability history is also a positive sign, implying a history of secure development or prompt patching of past issues. Despite the robust defenses identified, the unescaped output is a weakness that warrants attention. The plugin's minimal attack surface and secure data handling practices are commendable, but the output escaping issue presents a tangible risk that could be exploited.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Bank Melli EDD gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bank Melli EDD gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

Bank Melli EDD gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedMelli_for_EDD.php:21
actionadmin_menuMelli_for_EDD.php:28
filteredd_rial_currency_filter_afterMelli_for_EDD.php:60
filteredd_payment_gatewaysMelli_for_EDD.php:69
filteredd_melli_gate_cc_formMelli_for_EDD.php:76
actionedd_gateway_melli_gateMelli_for_EDD.php:166
actioninitMelli_for_EDD.php:265
filteredd_settings_gatewaysMelli_for_EDD.php:302
Maintenance & Trust

Bank Melli EDD gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 13, 2018
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Bank Melli EDD gateway Developer Profile

Javad Ehteshami

6 plugins · 90 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bank Melli EDD gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bank-melli-edd-gateway/images/icon.png

HTML / DOM Fingerprints

Shortcode Output
<html dir=rtl><meta http-equiv="Content-Language" content="fa"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
FAQ

Frequently Asked Questions about Bank Melli EDD gateway