Beanstream for WooCommerce Security & Risk Analysis

wordpress.org/plugins/beanstream-gateway-for-woocommerce

A Payment Gateway for WooCommerce allowing you to take credit card payments using Beanstream.

30 active installs v1.0 PHP + WP 3.5.0+ Updated Mar 14, 2015
beanstreamcredit-cardecommercepayment-gatewaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Beanstream for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Beanstream for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "beanstream-gateway-for-woocommerce" plugin version 1.0 appears to have a generally strong security posture based on the provided static analysis. There are no detected entry points like AJAX handlers, REST API routes, or shortcodes exposed without authentication, and no critical code signals like dangerous functions or raw SQL queries. The absence of known vulnerabilities in its history further contributes to this positive outlook.

However, the analysis does raise some concerns. A significant portion of the code, 100%, exhibits issues with output escaping, meaning that data displayed to users might not be properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-controlled data is ever introduced into these outputs. Furthermore, the plugin makes two external HTTP requests, which, while not inherently a vulnerability, can be a vector for other attacks if not handled securely, especially if the target endpoints are compromised or if data sent to them is not properly validated or escaped.

While the plugin has no recorded vulnerabilities, the lack of rigorous output escaping is a notable weakness. The absence of nonces and capability checks, while not directly flagged as issues due to the zero attack surface, means that if any new entry points were to be added in future versions without proper security considerations, they could be immediately vulnerable. The overall security is good in terms of attack vectors, but the output escaping and external requests warrant careful attention.

Key Concerns

  • Output escaping is not implemented
  • External HTTP requests made
Vulnerabilities
None known

Beanstream for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Beanstream for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Beanstream for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterwoocommerce_payment_gatewaysbeanstream-for-woocommerce.php:50
actionwoocommerce_update_options_payment_gatewaysincludes\classes\class-beanstream-gateway.php:58
actionadmin_noticesincludes\classes\class-beanstream-gateway.php:60
actionwp_enqueue_scriptsincludes\classes\class-beanstream-gateway.php:61
actionwoocommerce_credit_card_form_startincludes\classes\class-beanstream-gateway.php:62
Maintenance & Trust

Beanstream for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.0
Last updatedMar 14, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Beanstream for WooCommerce Developer Profile

Velmurugan Kuberan

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Beanstream for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/beanstream-for-woocommerce/assets/images/credits.png
Version Parameters
beanstream-for-woocommerce/assets/css/beanstream-wc-gateway.css?ver=beanstream-for-woocommerce/assets/js/beanstream-wc-gateway.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-merchant-iddata-api-versiondata-platformdata-testmodedata-saved-cards
JS Globals
beanstream_gateway_params
FAQ

Frequently Asked Questions about Beanstream for WooCommerce