Credit Card Number Generator Security & Risk Analysis

wordpress.org/plugins/credit-card-number-generator

Generate and Validate dummy credit card numbers for all well-known card issuers like MasterCard, Visa, JCB, Discover, American Express, etc.

70 active installs v1.0.8 PHP 5.3+ WP 4.0+ Updated Dec 10, 2024
credit-card-numberdummy-card-numbernumber-generatornumber-validatorpayment-gateway-testing
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Credit Card Number Generator Safe to Use in 2026?

Generally Safe

Score 92/100

Credit Card Number Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'credit-card-number-generator' plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, conducting all SQL queries with prepared statements, and not making external HTTP requests. The absence of any recorded vulnerabilities in its history is also a strong indicator of a generally secure development approach.

However, the static analysis reveals significant concerns, primarily related to its attack surface. Two AJAX handlers are present without authentication checks, representing direct entry points for potential malicious activity. Furthermore, one taint flow was found with unsanitized paths, which, although not classified as critical or high, still poses a risk if user-supplied data is involved. The plugin also only has one capability check across all entry points, which is insufficient to protect all of its functionalities.

While the plugin has no known CVEs and a clean vulnerability history, the presence of unprotected AJAX handlers and unsanitized taint flows are notable weaknesses. A balanced conclusion suggests that while the core logic might be sound, the implementation of security checks for its interactive components needs improvement to mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
  • Limited capability checks
Vulnerabilities
None known

Credit Card Number Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Credit Card Number Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
52 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped70 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ccng_credit_card_edit_callback (admin\class-credit-card-number-generator-admin.php:398)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Credit Card Number Generator Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

noprivwp_ajax_wli_credit_card_editadmin\class-credit-card-number-generator-admin.php:18
authwp_ajax_wli_credit_card_editadmin\class-credit-card-number-generator-admin.php:19

Shortcodes 2

[ccng_credit_cards] public\credit-card-number-generator-public.php:36
[ccng_credit_cards_validate] public\credit-card-number-generator-public.php:71
WordPress Hooks 8
actionadmin_enqueue_scriptsadmin\class-credit-card-number-generator-admin.php:9
actionwp_headadmin\class-credit-card-number-generator-admin.php:12
actionadmin_menuadmin\class-credit-card-number-generator-admin.php:15
filterplugin_action_links_credit-card-number-generator/credit-card-number-generator.phpadmin\class-credit-card-number-generator-admin.php:22
filteradmin_footer_textadmin\class-credit-card-number-generator-admin.php:28
actionwidgets_initadmin\class-credit-card-number-generator-widget.php:161
actionwidgets_initadmin\class-credit-card-number-validator-widget.php:101
filterpre_set_site_transient_update_pluginscredit-card-number-generator.php:50
Maintenance & Trust

Credit Card Number Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 10, 2024
PHP min version5.3
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Credit Card Number Generator Developer Profile

WeblineIndia

13 plugins · 5K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
54 days
View full developer profile
Detection Fingerprints

How We Detect Credit Card Number Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/credit-card-number-generator/assets/admin/ccng-admin-notices.css/wp-content/plugins/credit-card-number-generator/assets/js/install-plugin-ccng.js/wp-content/plugins/credit-card-number-generator/assets/js/clipboard.min.js/wp-content/plugins/credit-card-number-generator/assets/js/wli_card.js/wp-content/plugins/credit-card-number-generator/assets/css/style.css
Script Paths
/wp-content/plugins/credit-card-number-generator/assets/js/install-plugin-ccng.js/wp-content/plugins/credit-card-number-generator/assets/js/clipboard.min.js/wp-content/plugins/credit-card-number-generator/assets/js/wli_card.js
Version Parameters
credit-card-number-generator/assets/admin/ccng-admin-notices.css?ver=credit-card-number-generator/assets/js/install-plugin-ccng.js?ver=credit-card-number-generator/assets/js/clipboard.min.js?ver=credit-card-number-generator/assets/js/wli_card.js?ver=credit-card-number-generator/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
ccng-plugin-ctaccng-headingshow-other-plugincustom-bulletbutton-installwrap-ccnginner-ccngleft-box-ccng
Data Attributes
id="xml-plugin-banner"id="open-install-ccng"
JS Globals
admin_ajax_params
FAQ

Frequently Asked Questions about Credit Card Number Generator