Charge Anywhere Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/charge-anywhere-payment-gateway-for-woocommerce

Charge Anywhere payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.

20 active installs v4.2 PHP 7.4+ WP 5.0+ Updated Sep 11, 2025
ach-paymentscharge-anywherecredit-cardspayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Charge Anywhere Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Charge Anywhere Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "charge-anywhere-payment-gateway-for-woocommerce" plugin, version 4.2, demonstrates a generally strong security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history are positive indicators. The code adheres to good practices by exclusively using prepared statements for SQL queries and generally implements output escaping effectively, with only a small percentage of outputs potentially being unescaped. Furthermore, the plugin has a very limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks.

Key Concerns

  • Two unsanitized path flows identified.
  • No nonce checks detected.
  • Minor output escaping concern.
Vulnerabilities
None known

Charge Anywhere Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Charge Anywhere Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
29 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

76% escaped38 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
generate_authorize_form (includes\class-wc-gateway-chargeanywhere.php:1846)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Charge Anywhere Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionwoocommerce_order_status_completedincludes\class-wc-gateway-chargeanywhere.php:90
filterwoocommerce_payment_complete_order_statusincludes\class-wc-gateway-chargeanywhere.php:92
actionwoocommerce_api_wc_gateway_chargeanywhereincludes\class-wc-gateway-chargeanywhere.php:94
actionvalid-authorize-requestincludes\class-wc-gateway-chargeanywhere.php:95
actionwoocommerce_update_options_payment_gatewaysincludes\class-wc-gateway-chargeanywhere.php:101
actionwoocommerce_receipt_chargeanywhereincludes\class-wc-gateway-chargeanywhere.php:104
filterwc_get_price_decimalsincludes\class-wc-gateway-chargeanywhere.php:879
actionplugins_loadedindex.php:35
filterwoocommerce_payment_gatewaysindex.php:38
actionwoocommerce_blocks_loadedindex.php:41
actionbefore_woocommerce_initindex.php:43
filterwoocommerce_custom_order_tables_compatibleindex.php:49
actionwoocommerce_blocks_payment_method_type_registrationindex.php:116
actionadmin_enqueue_scriptsindex.php:142
actionwoocommerce_cart_calculate_feesindex.php:147
actionadmin_footerindex.php:229
actionadmin_footerindex.php:445
actionwoocommerce_review_order_before_paymentindex.php:503
actionwoocommerce_sort_fees_callbackindex.php:525
filtercaw_bypass_double_refund_validationindex.php:532
Maintenance & Trust

Charge Anywhere Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 11, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Charge Anywhere Payment Gateway for WooCommerce Developer Profile

tsmires

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Charge Anywhere Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/charge-anywhere-payment-gateway-for-woocommerce/includes/js/chargeanywhere-admin.js/wp-content/plugins/charge-anywhere-payment-gateway-for-woocommerce/includes/js/chargeanywhere-frontend-legacy.js
Script Paths
wp-content/plugins/charge-anywhere-payment-gateway-for-woocommerce/includes/js/chargeanywhere-admin.jswp-content/plugins/charge-anywhere-payment-gateway-for-woocommerce/includes/js/chargeanywhere-frontend-legacy.js
Version Parameters
chargeanywhere-frontend-legacy.js?ver=4.0

HTML / DOM Fingerprints

JS Globals
CA_handler_scriptwc-chargeanywhere-script
FAQ

Frequently Asked Questions about Charge Anywhere Payment Gateway for WooCommerce