Craftgate Payment Gateway Security & Risk Analysis

wordpress.org/plugins/craftgate-payment-gateway

Craftgate ödeme geçidini kullanarak WooCommerce üzerinden kolayca ödeme almanızı sağlayan teknik entegrasyon.

10 active installs v1.0.13 PHP 5.6+ WP 4.4+ Updated Dec 24, 2024
odeme-gecidicraftgatepayment-gatewaypayment-orchestration
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Craftgate Payment Gateway Safe to Use in 2026?

Generally Safe

Score 92/100

Craftgate Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "craftgate-payment-gateway" v1.0.13 exhibits a mixed security posture. On the positive side, there are no known CVEs, indicating a generally clean history and likely good development practices regarding known vulnerabilities. The static analysis shows a complete absence of a traditional attack surface from AJAX handlers, REST API routes, shortcodes, and cron events, which is a significant strength. Furthermore, all SQL queries are prepared, and there are no external HTTP requests, reducing common attack vectors. However, several areas raise concerns. The output escaping is alarmingly low at only 13%, meaning a large percentage of output is likely unescaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of 3 unsanitized paths in the taint analysis, even without critical or high severity, suggests potential issues where user-supplied data might be improperly handled, leading to unexpected behavior or security flaws. The lack of nonce checks and capability checks across any entry points, combined with the 0 total entry points without auth checks (which seems to imply there are no protected entry points if there are no entry points at all), suggests a potential over-reliance on the assumption that no external interaction is needed, which could be problematic if new entry points are ever introduced or if indirect pathways exist. The single file operation also warrants closer inspection for potential path traversal or insecure file handling.

Key Concerns

  • Low output escaping percentage
  • Unsanitized paths in taint analysis
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Craftgate Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Craftgate Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
7
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

13% escaped8 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
init_woocommerce_craftgate_gateway (craftgate-payment-gateway.php:29)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Craftgate Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedcraftgate-payment-gateway.php:24
actionwoocommerce_receipt_craftgate_gatewaycraftgate-payment-gateway.php:137
actionwoocommerce_api_craftgate_gateway_callbackcraftgate-payment-gateway.php:138
actionwoocommerce_api_craftgate_gateway_webhookcraftgate-payment-gateway.php:139
actionwoocommerce_admin_order_data_after_billing_addresscraftgate-payment-gateway.php:770
filterwoocommerce_payment_gatewayscraftgate-payment-gateway.php:784
filterplugin_action_linkscraftgate-payment-gateway.php:806
actionbefore_woocommerce_initcraftgate-payment-gateway.php:828
actionbefore_woocommerce_initcraftgate-payment-gateway.php:829
actionwoocommerce_blocks_payment_method_type_registrationcraftgate-payment-gateway.php:841
actionwoocommerce_blocks_loadedcraftgate-payment-gateway.php:850
actionwp_enqueue_scriptscraftgate-payment-gateway.php:861
Maintenance & Trust

Craftgate Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedDec 24, 2024
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Craftgate Payment Gateway Developer Profile

Craftgate

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Craftgate Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/craftgate-payment-gateway/assets/images/card-brands.png
Version Parameters
craftgate-payment-gateway/assets/images/card-brands.png?ver=

HTML / DOM Fingerprints

Data Attributes
iframe src
JS Globals
window.addEventListener
REST Endpoints
/wp-json/craftgate_gateway/
FAQ

Frequently Asked Questions about Craftgate Payment Gateway