Card Transfer Gateway Security & Risk Analysis

wordpress.org/plugins/card-transfer-gateway

The Card Transfer Gateway plugin is a very simple plugin for users, which eliminates the need for online payment gateways.

700 active installs v1.0.1 PHP + WP 3.3.0+ Updated Aug 4, 2025
card-to-cardcard-transfer%da%a9%d8%a7%d8%b1%d8%aa-%d8%a8%d9%87-%da%a9%d8%a7%d8%b1%d8%aa%d8%a7%d9%86%d8%aa%d9%82%d8%a7%d9%84-%da%a9%d8%a7%d8%b1%d8%aa%db%8c
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Card Transfer Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Card Transfer Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "card-transfer-gateway" v1.0.1 plugin exhibits a generally good security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are exclusively using prepared statements, and a high percentage of output is properly escaped. The absence of file operations, external HTTP requests, and no recorded vulnerabilities or CVEs further contribute to this positive assessment. However, the complete lack of nonce checks and capability checks across all identified entry points is a significant concern. While the attack surface appears small (0 AJAX handlers, 0 REST API routes, 0 shortcodes), any potential future vulnerabilities in these areas, or if the cron event itself has exploitable logic, would be entirely unprotected from unauthorized access or manipulation. This lack of fundamental security controls represents a critical weakness that could be easily exploited if an attacker finds a way to trigger the plugin's functionality without proper authorization.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
  • High percentage of unescaped output (24%)
Vulnerabilities
None known

Card Transfer Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Card Transfer Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped25 total outputs
Attack Surface

Card Transfer Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptscard-transfer-gateway.php:48
actionwp_enqueue_scriptscard-transfer-gateway.php:62
filtercron_schedulesinc\cronjobs.php:9
actionctgfree_cronjob_update_order_statuses_cron_hookinc\cronjobs.php:10
actionplugins_loadedinc\gateway.php:5
actioninitinc\gateway.php:9
filterwc_order_statusesinc\gateway.php:10
filterwoocommerce_payment_gatewaysinc\gateway.php:13

Scheduled Events 1

ctgfree_cronjob_update_order_statuses_cron_hook
Maintenance & Trust

Card Transfer Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 4, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs700
Developer Profile

Card Transfer Gateway Developer Profile

Wipna

1 plugin · 700 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Card Transfer Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/card-transfer-gateway/assets/css/dashboard.css/wp-content/plugins/card-transfer-gateway/assets/css/ctg-style.css
Version Parameters
card-transfer-gateway/assets/css/dashboard.css?ver=1.0.1card-transfer-gateway/assets/css/ctg-style.css?ver=1.0.1

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Card Transfer Gateway