Cashflows for WooCommerce Security & Risk Analysis

wordpress.org/plugins/cashflows-payments-by-ideal-checkout

Cashflows Payments Gateway for WooCommerce

700 active installs v2.3.6.4 PHP 7.4+ WP 5.8+ Updated Jan 19, 2026
cashflowscreditcardpaymentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cashflows for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Cashflows for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of "cashflows-payments-by-ideal-checkout" v2.3.6.4 indicates a generally strong security posture. The plugin exhibits excellent practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having a very high percentage of properly escaped outputs. The absence of any identified taint flows or known CVEs further strengthens this positive outlook, suggesting the developers prioritize secure coding. However, a notable concern arises from the complete lack of nonce checks and capability checks. This means that even though there are no identified entry points in the static analysis, if any were to be discovered or introduced in the future, they would be entirely unprotected against CSRF attacks and unauthorized access. The plugin's minimal attack surface, as reported (0 AJAX, 0 REST API, etc.), significantly mitigates this risk for now, but it represents a critical area for potential improvement. In conclusion, while the current version is remarkably secure against known threats and implements many best practices, the absence of critical security checks leaves it vulnerable to future undiscovered vulnerabilities or modifications.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Cashflows for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cashflows for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
7
External Requests
2
Bundled Libraries
0

Output Escaping

95% escaped19 total outputs
Attack Surface

Cashflows for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionwoocommerce_api_iccf_gateway_returncontrollers\woocommerce-cashflows.php:19
actionwoocommerce_api_iccf_gateway_return_failurecontrollers\woocommerce-cashflows.php:20
actionwoocommerce_api_iccf_gateway_notifycontrollers\woocommerce-cashflows.php:21
actionadmin_noticesic-cashflows-for-woo.php:57
actionadmin_noticesic-cashflows-for-woo.php:70
filterplugin_row_metaic-cashflows-for-woo.php:81
actionplugins_loadedic-cashflows-for-woo.php:93
filterwoocommerce_payment_gatewaysic-cashflows-for-woo.php:105
actionbefore_woocommerce_initic-cashflows-for-woo.php:131
actionwoocommerce_blocks_payment_method_type_registrationic-cashflows-for-woo.php:145
actionwoocommerce_blocks_loadedic-cashflows-for-woo.php:156
filterwoocommerce_get_settings_pagesic-cashflows-for-woo.php:177
filterwoocommerce_get_settings_cashflows_settings_tabic-cashflows-for-woo.php:319
actionwoocommerce_admin_field_cashflows_logs_rendereric-cashflows-for-woo.php:359
Maintenance & Trust

Cashflows for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 19, 2026
PHP min version7.4
Downloads14K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

Cashflows for WooCommerce Developer Profile

Cashflows

1 plugin · 700 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cashflows for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/css/blocks.style.css/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/cards.js/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/paypal.js/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/frontend.js
Script Paths
/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/cards.js/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/paypal.js/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/frontend.js
Version Parameters
/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/css/blocks.style.css?ver=/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/cards.js?ver=/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/paypal.js?ver=/wp-content/plugins/cashflows-payments-by-ideal-checkout/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
cashflows_card_gateway_formcashflows_paypal_gateway_form
HTML Comments
<!-- Block output if accessed directly --><!-- Path without trailing slash --><!-- URL With trailing slash --><!-- Define the plugin version -->+16 more
Data Attributes
data-gateway_id="cashflows_card"data-gateway_id="cashflows_paypal"
JS Globals
window.CashflowsCardswindow.CashflowsPaypal
FAQ

Frequently Asked Questions about Cashflows for WooCommerce