kevin. Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/e-commerce-payment-gateway-kevin

kevin. Payment Gateway plugin for WooCommerce. Let your customers make fast, simple and secure payments directly from their bank accounts across Europ …

30 active installs v4.2.8 PHP 7.0+ WP 5.4+ Updated Unknown
ecommerce-payment-gatewaypayment-gatewaywoocommercewoocommerce-payment-gatewaywoocommerce-payments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is kevin. Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

kevin. Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "e-commerce-payment-gateway-kevin" plugin v4.2.8 exhibits a generally positive security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a well-defined and restricted attack surface. Furthermore, the code's adherence to prepared statements for all SQL queries and the presence of numerous output escaping instances are strong indicators of good development practices aimed at preventing common vulnerabilities like SQL injection and cross-site scripting.

However, several areas warrant attention. The complete lack of nonce checks and capability checks is a significant concern, especially if the plugin handles any sensitive data or actions, as it leaves potential avenues for unauthorized access or execution. While taint analysis reported no critical or high severity flows, the analysis itself reported zero flows analyzed, making this result less conclusive. The relatively low percentage of properly escaped output (63%) suggests that a portion of the plugin's output may be vulnerable to XSS attacks. The plugin's history of zero known CVEs is a positive sign, suggesting a track record of security, but this alone does not negate the risks identified in the static analysis.

In conclusion, the plugin demonstrates a good foundation by minimizing its attack surface and employing secure database practices. The absence of historical vulnerabilities is encouraging. Nevertheless, the critical absence of nonce and capability checks, coupled with the moderate rate of unescaped output, introduces notable risks that should be addressed. A more comprehensive taint analysis would also be beneficial to confirm the absence of deeper vulnerabilities.

Key Concerns

  • No nonce checks
  • No capability checks
  • Only 63% of output properly escaped
  • Taint analysis not conclusive (0 flows analyzed)
Vulnerabilities
None known

kevin. Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

kevin. Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
43 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
1
Bundled Libraries
0

Output Escaping

63% escaped68 total outputs
Attack Surface

kevin. Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionbefore_woocommerce_initgetkevin.php:35
actionupgrader_process_completegetkevin.php:46
actionplugins_loadedgetkevin.php:48
filterwoocommerce_payment_gatewayssrc\Bootstrap.php:37
actionadmin_noticessrc\Bootstrap.php:61
actionwoocommerce_api_kevin_returnsrc\Gateway\BankPaymentGateway.php:77
filterwoocommerce_thankyou_order_received_textsrc\Gateway\BankPaymentGateway.php:82
filterwoocommerce_thankyou_order_received_textsrc\Gateway\CardPaymentGateway.php:59
Maintenance & Trust

kevin. Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedUnknown
PHP min version7.0
Downloads5K

Community Trust

Rating30/100
Number of ratings2
Active installs30
Developer Profile

kevin. Payment Gateway for WooCommerce Developer Profile

kevin EU

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect kevin. Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-commerce-payment-gateway-kevin/assets/js/backend/kevin-bank-payment-settings.js/wp-content/plugins/e-commerce-payment-gateway-kevin/assets/css/kevin-styles.css/wp-content/plugins/e-commerce-payment-gateway-kevin/assets/css/kevin-bank-grid.css
Script Paths
assets/js/backend/kevin-bank-payment-settings.js
Version Parameters
e-commerce-payment-gateway-kevin/assets/js/backend/kevin-bank-payment-settings.js?ver=e-commerce-payment-gateway-kevin/assets/css/kevin-styles.css?ver=e-commerce-payment-gateway-kevin/assets/css/kevin-bank-grid.css?ver=

HTML / DOM Fingerprints

CSS Classes
kevin-bank-payment-settings
FAQ

Frequently Asked Questions about kevin. Payment Gateway for WooCommerce