Due.com E-Commerce Payment Gateway Security & Risk Analysis

wordpress.org/plugins/duecom-e-commerce-payment-gateway

Be sure to checkout our tutorial on using this plugin.

10 active installs v1.4.4 PHP + WP + Updated Oct 10, 2018
due-alipay-bitcoin-for-woocommercedue-alipay-for-woocommercedue-payment-gateway-for-woocommercedue-woocommerce-pluginwoocommerce-plugin-due-alipay-bitcoin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Due.com E-Commerce Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Due.com E-Commerce Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'duecom-e-commerce-payment-gateway' plugin version 1.4.4 exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, external HTTP requests, file operations, and SQL queries that do not use prepared statements indicates good coding practices. The taint analysis showing zero flows with unsanitized paths further reinforces this positive assessment. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a consistent effort towards maintaining security.

However, there are areas for improvement. A significant concern is the complete lack of capability checks and nonce checks. This implies that many operations within the plugin might be accessible to users without proper authorization, especially if new entry points are introduced in future versions. While the current attack surface is zero, relying on this without inherent permission checks is a risky assumption. The unescaped output rate, while not critical, also presents a potential area for Cross-Site Scripting (XSS) vulnerabilities if malicious data is not properly handled by the theme or other plugins interacting with these outputs.

In conclusion, the plugin is currently in a good state with no identified critical vulnerabilities and a history of stability. The developers have employed several good security practices. Nevertheless, the complete absence of capability and nonce checks on all entry points, despite the current zero attack surface, represents a significant oversight that could lead to vulnerabilities if the attack surface expands or if unexpected interactions occur. The unescaped output, while minor, should also be addressed for complete robustness.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • 25% of output not properly escaped
Vulnerabilities
None known

Due.com E-Commerce Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Due.com E-Commerce Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped20 total outputs
Attack Surface

Due.com E-Commerce Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwp_enqueue_scriptsincludes\class-wc-gateway-duecom.php:69
actionwoocommerce_payment_completeincludes\class-wc-gateway-duecom.php:78
actionwcs_resubscribe_order_createdincludes\class-wc-gateway-duecom.php:93
filterwoocommerce_subscription_payment_metaincludes\class-wc-gateway-duecom.php:99
filterwoocommerce_subscription_validate_payment_metaincludes\class-wc-gateway-duecom.php:104
filterwoocommerce_my_subscriptions_payment_methodincludes\class-wc-gateway-duecom.php:110
actionwp_headincludes\class-wc-gateway-duecom.php:285
actionplugins_loadedwoocommerce-gateway-duecom.php:30
actionwp_enqueue_scriptswoocommerce-gateway-duecom.php:31
filterwoocommerce_payment_gatewayswoocommerce-gateway-duecom.php:32
Maintenance & Trust

Due.com E-Commerce Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 10, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Due.com E-Commerce Payment Gateway Alternatives

No alternatives data available yet.

Developer Profile

Due.com E-Commerce Payment Gateway Developer Profile

Due

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Due.com E-Commerce Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duecom-e-commerce-payment-gateway/assets/css/style.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Due.com E-Commerce Payment Gateway