CashBill.pl – Płatności WooCommerce Security & Risk Analysis

wordpress.org/plugins/cashbill-payment-method

Dedykowane rozwiązanie integrujące najpopularniejsze metody płatności. Dzięki tej wtyczce możesz w atrakcyjny sposób prezentować siatkę z logotypami b …

900 active installs v3.3.1 PHP + WP 5.0.0+ Updated Nov 12, 2025
cashbillpaymentpayment-gatewayplatnosciwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 22, 2025
Safety Verdict

Is CashBill.pl – Płatności WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

CashBill.pl – Płatności WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 22, 2025Updated 4mo ago
Risk Assessment

The cashbill-payment-method plugin version 3.3.1 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by having no identified dangerous functions, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. The presence of nonce and capability checks, along with a relatively small attack surface with zero unprotected entry points, are also encouraging signs. However, a significant concern arises from the output escaping. With 54 total outputs and only 20% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially given that the plugin's historical vulnerabilities are primarily of this type.

The taint analysis reveals 2 flows with unsanitized paths, though they are not categorized as critical or high severity. This, combined with the poor output escaping, suggests that while direct critical vulnerabilities might not be immediately apparent in this version, there's a clear pathway for attackers to inject malicious scripts if improperly handled user input is rendered on the frontend. The vulnerability history, while currently showing no unpatched CVEs, indicates a past pattern of XSS issues, which should be a warning sign. The fact that the last vulnerability was dated in the future (2025-09-22) is likely a data anomaly, but the historical trend of XSS is a concern.

In conclusion, while the plugin has implemented some robust security measures like prepared statements and authorization checks, the widespread lack of proper output escaping poses a significant risk. Coupled with the historical prevalence of XSS, this plugin requires careful monitoring and potential remediation to ensure user data and site integrity are protected. The potential for unpatched vulnerabilities in the future, given past occurrences, also warrants attention.

Key Concerns

  • 20% proper output escaping
  • 2 flows with unsanitized paths
  • History of XSS vulnerabilities
Vulnerabilities
1

CashBill.pl – Płatności WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53455medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CashBill.pl - Płatności WooCommerce <= 3.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025 Patched in 3.3.0 (8d)
Code Analysis
Analyzed Mar 16, 2026

CashBill.pl – Płatności WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
43
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped54 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save (model\CashBillSettings.php:65)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CashBill.pl – Płatności WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menucontroller\CashBillSettings.php:10
actionadmin_postcontroller\CashBillSettings.php:11
actionadmin_noticescontroller\CashBillSettings.php:12
filterwoocommerce_payment_gatewayswoocommerce-cashbill.php:26
actionwoocommerce_blocks_payment_method_type_registrationwoocommerce-cashbill.php:95
actionadmin_enqueue_scriptswoocommerce-cashbill.php:119
actionplugins_loadedwoocommerce-cashbill.php:120
actionplugins_loadedwoocommerce-cashbill.php:121
actionwoocommerce_blocks_loadedwoocommerce-cashbill.php:122
actionwoocommerce_api_cashbill_paymentwoocommerce-cashbill.php:124
Maintenance & Trust

CashBill.pl – Płatności WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs900
Developer Profile

CashBill.pl – Płatności WooCommerce Developer Profile

CashBill

1 plugin · 900 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect CashBill.pl – Płatności WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cashbill-payment-method/css/admin.css

HTML / DOM Fingerprints

CSS Classes
cashbill-payment-method
Data Attributes
data-gateway_iddata-order_iddata-amountdata-customer_iddata-customer_emaildata-currency+6 more
JS Globals
cashbill_payment_settings
REST Endpoints
/wp-json/cashbill-payment-method/v1/payment
FAQ

Frequently Asked Questions about CashBill.pl – Płatności WooCommerce