Estonian Banklinks for WooCommerce Security & Risk Analysis

wordpress.org/plugins/estonian-banklinks-for-woocommerce

Extends WooCommerce with most commonly used Estonian banklinks. All in one.

400 active installs v1.6.1 PHP + WP 4.1+ Updated Dec 2, 2024
banklinkestoniapangalinkpayment-gatewaywoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Estonian Banklinks for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Estonian Banklinks for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "estonian-banklinks-for-woocommerce" v1.6.1 plugin exhibits a generally good security posture with no recorded CVEs and a low number of external HTTP requests. The code signals indicate a diligent approach to SQL query protection, with all queries utilizing prepared statements. Furthermore, the plugin demonstrates a strong commitment to output escaping, with 85% of identified outputs being properly sanitized, minimizing the risk of cross-site scripting (XSS) vulnerabilities.

However, the static analysis reveals a significant concern regarding taint analysis. Two flows were analyzed, and both were found to have unsanitized paths, with one classified as high severity. This indicates a potential for data to be improperly handled or exposed. Additionally, the complete absence of nonce checks and capability checks across all entry points (although the entry point count is zero) suggests a lack of standard security mechanisms that could be exploited if new entry points were introduced or if existing functionalities were expanded without these checks. The plugin also lacks explicit protection for its entry points, even though none are currently identified.

Key Concerns

  • High severity taint flow with unsanitized paths
  • Taint flows with unsanitized paths (2 total)
  • No nonce checks detected
  • No capability checks detected
  • Unescaped output (15% of 13 outputs)
Vulnerabilities
None known

Estonian Banklinks for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Estonian Banklinks for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
2
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

85% escaped13 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<class-wc-banklink-maksekeskus> (includes\abstracts\class-wc-banklink-maksekeskus.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Estonian Banklinks for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedestonian-banklinks-for-woocommerce.php:59
actionwp_enqueue_scriptsestonian-banklinks-for-woocommerce.php:60
actioninitestonian-banklinks-for-woocommerce.php:61
filterwoocommerce_payment_gatewaysestonian-banklinks-for-woocommerce.php:72
actionbefore_woocommerce_initestonian-banklinks-for-woocommerce.php:78
actionwoocommerce_checkout_update_order_metaincludes\gateways\class-wc-banklink-maksekeskus-billing-api.php:26
actionwoocommerce_checkout_update_order_reviewincludes\gateways\class-wc-banklink-maksekeskus-billing-api.php:27
filterwoocommerce_before_template_partincludes\gateways\class-wc-banklink-maksekeskus-billing-api.php:28
Maintenance & Trust

Estonian Banklinks for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 2, 2024
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings7
Active installs400
Developer Profile

Estonian Banklinks for WooCommerce Developer Profile

Risto Niinemets

4 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Estonian Banklinks for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/estonian-banklinks-for-woocommerce/assets/css/style.css
Version Parameters
wc-gateway-estonia-banklink/assets/css/style.css?ver=1.5

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Estonian Banklinks for WooCommerce