
EveryPay Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/everypay-payment-gatewayAccept Credit Cards and Debit Cards on your WooCommerce store.
Is EveryPay Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100EveryPay Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "everypay-payment-gateway" plugin v3.8 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and demonstrates good practices in output escaping, with 84% of outputs properly escaped. It also avoids the use of dangerous functions and has a limited number of file operations and external HTTP requests. However, there are notable concerns regarding its attack surface. The plugin exposes 5 AJAX handlers, with a significant portion (2 out of 5) lacking authentication checks, presenting a potential entry point for unauthorized actions. While taint analysis shows no critical or high-severity flows, the presence of unprotected AJAX handlers is a direct risk.
The vulnerability history shows a clean slate, which is a strong indicator of diligent development and a commitment to security. This suggests that past versions may have been well-maintained or that the codebase is generally robust. Despite the lack of past vulnerabilities, the current code analysis reveals a weakness in the handling of AJAX requests. The presence of unprotected AJAX endpoints, even without a history of exploitation, represents a clear and present danger that could be leveraged if an attacker discovers them. In conclusion, while the plugin has strengths in its lack of historical vulnerabilities and good output sanitization, the unprotected AJAX handlers are a significant weakness that requires immediate attention to improve its overall security.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of SQL queries using prepared statements
- Limited nonce checks on entry points
- Limited capability checks on entry points
EveryPay Payment Gateway for WooCommerce Security Vulnerabilities
EveryPay Payment Gateway for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
EveryPay Payment Gateway for WooCommerce Attack Surface
AJAX Handlers 5
WordPress Hooks 10
Maintenance & Trust
EveryPay Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
EveryPay Payment Gateway for WooCommerce Alternatives
Payment Gateway of PayPal for WooCommerce
express-checkout-paypal-payment-gateway-for-woocommerce
Enable faster checkout with PayPal for WooCommerce. Add PayPal Express/PayPal Standard gateways that accept PayPal, Pay Later, debit & credit cards.
Music Store – Stripe Add On
music-store-stripe-add-on
Integrates the Stripe payment gateway with the Music Store for accepting payments with credit and debit cards.
Debitsuccess
debitsuccess
Accept all major credit cards directly on your WooCommerce site in a seamless and secure checkout environment with Debitsuccess Commerce.
PayU GPO Payment for WooCommerce
woo-payu-payment-gateway
PayU fast online payments for WooCommerce. Banks, BLIK, credit or debit cards, Installments, Apple Pay, Google Pay.
Asaas Gateway for WooCommerce
woo-asaas
Take transparent credit card and bank ticket payment checkouts on your store using Asaas.
EveryPay Payment Gateway for WooCommerce Developer Profile
1 plugin · 300 total installs
How We Detect EveryPay Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/everypay-payment-gateway/assets/css/everypay.css/wp-content/plugins/everypay-payment-gateway/assets/js/everypay.js/wp-content/plugins/everypay-payment-gateway/assets/js/everypay-iris.js/wp-content/plugins/everypay-payment-gateway/assets/js/everypay-applepay.js/wp-content/plugins/everypay-payment-gateway/assets/js/everypay-wc-gateway.jseverypay-payment-gateway/assets/css/everypay.css?ver=everypay-payment-gateway/assets/js/everypay.js?ver=everypay-payment-gateway/assets/js/everypay-iris.js?ver=everypay-payment-gateway/assets/js/everypay-applepay.js?ver=everypay-payment-gateway/assets/js/everypay-wc-gateway.js?ver=HTML / DOM Fingerprints
everypay-iris-formeverypay-card-formeverypay-token-formeverypay-applepay-button-wrapperdata-everypay-public-keydata-everypay-private-keydata-everypay-api-keydata-everypay-domainEveryPay/wp-json/everypay/v1/create_token/wp-json/everypay/v1/process_payment