CodeCareBD – Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway

CodeCareBD - Payment Gateway plugin integrates bKash, Nagad, Rocket, and Payoneer Payment Gateways with WooCommerce.

300 active installs v1.0 PHP 7.3+ WP 6.3+ Updated Feb 3, 2026
bkashnagadpayoneerrocketwoocommerce-payment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CodeCareBD – Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

CodeCareBD – Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

This plugin, "codecarebd-bkash-nagad-rocket-payoneer-gateway" v1.0, exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries executed without prepared statements, and a significant majority of properly escaped output are positive indicators. Furthermore, the plugin demonstrates good practice by including a nonce check and having no known historical vulnerabilities, suggesting a commitment to security over time.

However, a notable concern arises from the taint analysis, which identified one flow with unsanitized paths. While no critical or high severity issues were flagged in the taint analysis, an unsanitized path represents a potential entry point for malicious data to be processed without proper validation, which could lead to various vulnerabilities depending on how that data is subsequently used. The lack of capability checks on the identified entry points (even though the total number is zero) means that if any entry points were to be introduced in future versions, they might not be adequately protected against unauthorized access.

In conclusion, the plugin's current version is relatively secure due to its development practices and clean vulnerability history. The primary area for improvement lies in rigorously addressing the identified unsanitized path flow to eliminate potential risks. Future development should also prioritize implementing capability checks for any new entry points to maintain a robust security foundation.

Key Concerns

  • Flow with unsanitized paths
  • Lack of capability checks on entry points
Vulnerabilities
None known

CodeCareBD – Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CodeCareBD – Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
196 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped240 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
ccd_bkash_admin_order_data_function (ccd-payment-gateway.php:220)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CodeCareBD – Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterwoocommerce_payment_gatewaysccd-payment-gateway.php:30
actionplugins_loadedccd-payment-gateway.php:32
actionwoocommerce_checkout_update_order_metaccd-payment-gateway.php:34
actionwoocommerce_admin_order_data_after_billing_addressccd-payment-gateway.php:36
actionwoocommerce_order_details_after_customer_detailsccd-payment-gateway.php:38
filterwoocommerce_account_orders_columnsccd-payment-gateway.php:40
filtermanage_woocommerce_page_wc-orders_columnsccd-payment-gateway.php:42
actionmanage_shop_order_posts_custom_columnccd-payment-gateway.php:44
actionmanage_woocommerce_page_wc-orders_custom_columnccd-payment-gateway.php:46
actionwp_enqueue_scriptsccd-payment-gateway.php:49
actioninitccd-payment-gateway.php:52
filterwoocommerce_register_shop_order_post_statusesccd-payment-gateway.php:55
filterwc_order_statusesccd-payment-gateway.php:58
actionadmin_menuccd-payment-gateway.php:61
actionadmin_initccd-payment-gateway.php:62
actionwoocommerce_cart_calculate_feesccd-payment-gateway.php:85
actionadmin_noticesccd-payment-gateway.php:129
actionadmin_initccd-payment-gateway.php:147
actionwoocommerce_checkout_processccd-payment-gateway.php:561
filterwoocommerce_thankyou_order_received_textincludes\classes\CCD_Payment_Bkash.php:34
actionwoocommerce_email_before_order_tableincludes\classes\CCD_Payment_Bkash.php:35
filterwoocommerce_thankyou_order_received_textincludes\classes\CCD_Payment_Nagad.php:31
actionwoocommerce_email_before_order_tableincludes\classes\CCD_Payment_Nagad.php:32
filterwoocommerce_thankyou_order_received_textincludes\classes\CCD_Payment_Payoneer.php:28
actionwoocommerce_email_before_order_tableincludes\classes\CCD_Payment_Payoneer.php:29
filterwoocommerce_thankyou_order_received_textincludes\classes\CCD_Payment_Rocket.php:31
actionwoocommerce_email_before_order_tableincludes\classes\CCD_Payment_Rocket.php:32
Maintenance & Trust

CodeCareBD – Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 3, 2026
PHP min version7.3
Downloads11K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

CodeCareBD – Payment Gateway for WooCommerce Developer Profile

Shakil Ahamed

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CodeCareBD – Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/css/checkout.css/wp-content/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/js/checkout.js
Script Paths
/wp-content/plugins/codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/js/checkout.js
Version Parameters
codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/css/checkout.css?ver=codecarebd-bkash-nagad-rocket-payoneer-gateway/assets/js/checkout.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Begin cc-payment-gateway-domain --><!-- End cc-payment-gateway-domain -->
Data Attributes
data-gateway-id="ccd_bkash"data-gateway-id="ccd_nagad"data-gateway-id="ccd_rocket"data-gateway-id="ccd_payoneer"
FAQ

Frequently Asked Questions about CodeCareBD – Payment Gateway for WooCommerce