
3-D Secure Payment Gateway by CardinalCommerce Security & Risk Analysis
wordpress.org/plugins/cardinalcommerce-oneconnectOneConnect is your 3-D Secure Payment Gateway Plugin for use with your current payment service provider.
Is 3-D Secure Payment Gateway by CardinalCommerce Safe to Use in 2026?
Generally Safe
Score 85/1003-D Secure Payment Gateway by CardinalCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cardinalcommerce-oneconnect' plugin version 1.2.8 exhibits a seemingly secure posture based on the provided static analysis, with no identified attack surface through common entry points like AJAX, REST API, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, and vulnerabilities in its history suggests careful development and maintenance. The use of prepared statements for all SQL queries is a significant strength. However, a critical concern arises from the output escaping analysis, where 0% of the four identified outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever directly rendered without proper sanitization. The lack of nonce and capability checks, while not directly exploitable due to the zero attack surface, implies a lack of defensive coding practices that could become a risk if the plugin's functionality or entry points were to expand in future versions. The single external HTTP request also warrants scrutiny to ensure it's handled securely. In conclusion, while the plugin currently presents a low risk due to its limited attack surface and lack of historical vulnerabilities, the unescaped output is a significant weakness that needs immediate attention. The absence of robust authentication and sanitization checks on its minimal entry points also highlights potential future risks if the plugin evolves.
Key Concerns
- Unescaped output found
- Missing nonce checks
- Missing capability checks
- External HTTP request present
3-D Secure Payment Gateway by CardinalCommerce Security Vulnerabilities
3-D Secure Payment Gateway by CardinalCommerce Code Analysis
Output Escaping
3-D Secure Payment Gateway by CardinalCommerce Attack Surface
WordPress Hooks 3
Maintenance & Trust
3-D Secure Payment Gateway by CardinalCommerce Maintenance & Trust
Maintenance Signals
Community Trust
3-D Secure Payment Gateway by CardinalCommerce Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
SnapScan Payment Gateway
snapscan-online-payments
A free, safe, and secure payment integration where customers can pay via SnapScan or card with automatic WooCommerce payment reconciliation.
EveryPay Payment Gateway for WooCommerce
everypay-payment-gateway
Accept Credit Cards and Debit Cards on your WooCommerce store.
Scanpay for WooCommerce
scanpay-for-woocommerce
Accept payments in WooCommerce with a reliable and secure Scandinavian payment gateway.
Aircash for WooCommerce
aircash-for-woocommerce
We make payments even faster, safer and easier – 24/7! Simple to use and extra safe for you and your customers.
3-D Secure Payment Gateway by CardinalCommerce Developer Profile
1 plugin · 20 total installs
How We Detect 3-D Secure Payment Gateway by CardinalCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cardinalcommerce-oneconnect/cardinalcommerce-oneconnect.js/wp-content/plugins/cardinalcommerce-oneconnect/css/cardinal-admin-styles.css/wp-content/plugins/cardinalcommerce-oneconnect/css/cardinal-checkout-styles.csshttps://songbird.cardinalcommerce.com/edge/v1/songbird.jshttps://songbirdstag.cardinalcommerce.com/edge/v1/songbird.jscardinalcommerce-oneconnect/cardinalcommerce-oneconnect.js?ver=cardinalcommerce-oneconnect/css/cardinal-admin-styles.css?ver=cardinalcommerce-oneconnect/css/cardinal-checkout-styles.css?ver=HTML / DOM Fingerprints
cardinal-checkout-containercardinal-oneconnect-loaderdata-cardinal-payment-actiondata-cardinal-api-identifierdata-cardinal-org-unit-idCardinalSongbird