
CardGate Payments for WooCommerce Security & Risk Analysis
wordpress.org/plugins/cardgateCardGate Payment methods for WooCommerce
Is CardGate Payments for WooCommerce Safe to Use in 2026?
Generally Safe
Score 96/100CardGate Payments for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "cardgate" plugin version 4.1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices with 100% of its SQL queries utilizing prepared statements and the presence of nonce and capability checks. The absence of a large attack surface from unprotected AJAX handlers, REST API routes, shortcodes, and cron events is also commendable. However, concerns arise from the taint analysis, which reveals 3 flows with unsanitized paths, including 2 of high severity. This indicates potential vulnerabilities where user input is not properly validated or sanitized before being used in sensitive operations.
The plugin's vulnerability history, with 3 known CVEs including one high and two medium severity issues, further reinforces these concerns. The common vulnerability types point to persistent issues with improper neutralization of special elements, leading to SQL injection and cross-site scripting, as well as origin validation errors. While there are currently no unpatched vulnerabilities, the history suggests a pattern of susceptibility to these common web application security flaws.
In conclusion, while "cardgate" 4.1.1 has implemented some robust security measures, the presence of high-severity taint flows and a history of critical vulnerability types necessitate caution. The developer should prioritize addressing the identified unsanitized flows and continue to focus on secure coding practices to mitigate the risk of future exploits.
Key Concerns
- High severity taint flows found
- Medium severity CVEs historically
- Flows with unsanitized paths
- Inconsistent output escaping (61%)
CardGate Payments for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
CardGate Payments for WooCommerce <= 3.2.1 - Authenticated (Administrator+) SQL Injection
CardGate Payments for WooCommerce <= 3.2.1 - Reflected Cross-Site Scripting
CardGate Payments for WooCommerce <= 3.1.15 - Lack of Origin Validation
CardGate Payments for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CardGate Payments for WooCommerce Attack Surface
WordPress Hooks 14
Maintenance & Trust
CardGate Payments for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CardGate Payments for WooCommerce Alternatives
MakeCommerce for WooCommerce
makecommerce
Payment Gateway for Estonian, Latvian, Lithuanian and Finnish banks and Visa/MasterCard payments with single contract (by Maksekeskus). And more...
Cashflows for WooCommerce
cashflows-payments-by-ideal-checkout
Cashflows Payments Gateway for WooCommerce
PayPro Gateways – WooCommerce
paypro-gateways-woocommerce
With this plugin you easily add all PayPro payment gateways to your WooCommerce webshop.
Professional Payment Portal for WooCommerce
professional-payment-portal-for-woocommerce
One of the easiest and best ways to integration Rabobank in your WooCommerce webshop!
LivePayments – mobilPay Card WooCommerce Payment Gateway
wc-mobilpayments-card
LivePayments is a Credit & Debit Card WooCommerce Payment Gateway that uses the Romanian mobilPay payment processor.
CardGate Payments for WooCommerce Developer Profile
1 plugin · 200 total installs
How We Detect CardGate Payments for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cardgate/assets/css/cardgate.css/wp-content/plugins/cardgate/assets/js/cardgate.js/wp-content/plugins/cardgate/assets/js/cardgate.jscardgate/assets/css/cardgate.css?ver=cardgate/assets/js/cardgate.js?ver=HTML / DOM Fingerprints
cardgate-checkout-displaydata-cg-modedata-cg-siteiddata-cg-merchantiddata-cg-merchantapikeydata-cg-hashkeydata-cg-checkoutdisplay+14 morecardgate/wp-json/cardgate/v1/payment