Debitsuccess Security & Risk Analysis

wordpress.org/plugins/debitsuccess

Accept all major credit cards directly on your WooCommerce site in a seamless and secure checkout environment with Debitsuccess Commerce.

10 active installs v2.8 PHP + WP 3.6.1+ Updated Oct 20, 2015
australia-payment-gatewaycard-payment-woocommercedebitsuccessdebitsuccess-payment-gatewaygateway-for-woocommercepay-with-credit-card-debit-card-internet-banking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Debitsuccess Safe to Use in 2026?

Generally Safe

Score 85/100

Debitsuccess has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "debitsuccess" plugin v2.8 exhibits a concerning security posture due to significant vulnerabilities identified in its static analysis. While the plugin demonstrates good practices by avoiding dangerous functions and utilizing prepared statements for all SQL queries, these strengths are overshadowed by critical weaknesses. The most significant concern is the complete lack of output escaping, meaning any data displayed to users could potentially be manipulated, opening the door to cross-site scripting (XSS) attacks. Additionally, the presence of two AJAX handlers without any authentication or capability checks presents a direct pathway for unauthorized actions or information disclosure. The absence of nonce checks further exacerbates this risk. The plugin's vulnerability history is clean, with no recorded CVEs, which might suggest a relatively new or less targeted plugin. However, this lack of history should not be misinterpreted as a guarantee of security, especially given the severe flaws found in the current static analysis. The plugin's overall security needs significant improvement, particularly in output sanitization and input validation for its entry points.

Key Concerns

  • AJAX handlers without auth checks
  • Output escaping completely missing
  • Nonce checks missing
  • Capability checks missing
Vulnerabilities
None known

Debitsuccess Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Debitsuccess Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
46
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped46 total outputs
Attack Surface
2 unprotected

Debitsuccess Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_custom_instalment_pricegateway-debitsuccess.php:1395
noprivwp_ajax_custom_instalment_pricegateway-debitsuccess.php:1396
WordPress Hooks 15
actionplugins_loadedgateway-debitsuccess.php:24
actionwp_headgateway-debitsuccess.php:69
actionwp_footergateway-debitsuccess.php:70
actionadmin_noticesgateway-debitsuccess.php:71
actionwoocommerce_before_my_accountgateway-debitsuccess.php:72
actionwoocommerce_receipt_inspiregateway-debitsuccess.php:73
actionwoocommerce_update_options_payment_gatewaysgateway-debitsuccess.php:74
actionwp_enqueue_scriptsgateway-debitsuccess.php:76
actionscheduled_subscription_payment_inspiregateway-debitsuccess.php:77
filtercomments_clausesgateway-debitsuccess.php:123
filterwoocommerce_payment_gatewaysgateway-debitsuccess.php:1327
filterwoocommerce_ajax_loader_urlgateway-debitsuccess.php:1328
actionwoocommerce_cart_calculate_feesgateway-debitsuccess.php:1360
actionwoocommerce_cart_calculate_feesgateway-debitsuccess.php:1393
actionwoocommerce_before_calculate_totalsgateway-debitsuccess.php:1394
Maintenance & Trust

Debitsuccess Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedOct 20, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Debitsuccess Developer Profile

Debitsuccess

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Debitsuccess

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/debitsuccess/images/ds_logo2.png

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Debitsuccess