Duitku Payment Gateway Security & Risk Analysis

wordpress.org/plugins/duitku-social-payment-gateway

Do you want the best solution to accept Credit Cards, e-wallet, and Various Bank Transfers on your website? Our Payment Gateway for WooCommerce plugin …

800 active installs v2.11.14 PHP + WP 4.7+ Updated Mar 3, 2026
bcabriduitkumandiripaymentgateway
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 26, 2024
Download
Safety Verdict

Is Duitku Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Duitku Payment Gateway has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 26, 2024Updated 1mo ago
Risk Assessment

The plugin 'duitku-social-payment-gateway' v2.11.14 exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, file operations, and raw SQL queries are strong indicators of secure coding practices. Furthermore, the high percentage of properly escaped output and the use of prepared statements for all SQL queries demonstrate a commitment to preventing common web vulnerabilities. The limited attack surface, with no exposed AJAX handlers, REST API routes, or shortcodes, further reduces the potential for external exploitation.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Medium severity vulnerability history
Vulnerabilities
1

Duitku Payment Gateway Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-0631medium · 5.3Improper Access Control

Duitku Payment Gateway <= 2.11.6 - Missing Authorization via check_duitku_response

Feb 26, 2024 Patched in 2.11.7 (155d)
Code Analysis
Analyzed Mar 16, 2026

Duitku Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

91% escaped23 total outputs
Attack Surface

Duitku Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filterwoocommerce_settings_tabs_arrayincludes\admin\class-wc-duitku-settings.php:12
actionwoocommerce_settings_tabs_duitku_settingsincludes\admin\class-wc-duitku-settings.php:13
actionwoocommerce_update_options_duitku_settingsincludes\admin\class-wc-duitku-settings.php:14
actionwoocommerce_blocks_enqueue_checkout_blocks_scripts_afterincludes\admin\class-wc-duitku-settings.php:15
actionwoocommerce_initincludes\admin\class-wc-duitku-settings.php:16
actionwp_enqueue_scriptsincludes\admin\class-wc-duitku-settings.php:17
actionwoocommerce_cart_calculate_feesincludes\admin\class-wc-duitku-settings.php:18
actionwoocommerce_review_order_before_paymentincludes\admin\class-wc-duitku-settings.php:19
actionwoocommerce_review_order_before_paymentincludes\admin\class-wc-duitku-settings.php:22
actionplugins_loadedwoocommerce-gateway-duitku.php:127
actionwoocommerce_blocks_loadedwoocommerce-gateway-duitku.php:128
actionwp_enqueue_scriptswoocommerce-gateway-duitku.php:129
filterwoocommerce_payment_gatewayswoocommerce-gateway-duitku.php:148
actionwoocommerce_blocks_payment_method_type_registrationwoocommerce-gateway-duitku.php:243
Maintenance & Trust

Duitku Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 3, 2026
PHP min version
Downloads23K

Community Trust

Rating80/100
Number of ratings2
Active installs800
Developer Profile

Duitku Payment Gateway Developer Profile

rayhanduitku

4 plugins · 900 total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
155 days
View full developer profile
Detection Fingerprints

How We Detect Duitku Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duitku-social-payment-gateway/includes/assets/js/duitku_dom_manipulate.js
Script Paths
/wp-content/plugins/duitku-social-payment-gateway/includes/assets/js/duitku_dom_manipulate.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Duitku Payment Gateway