Экспресс Платежи: Интернет-Эквайринг Security & Risk Analysis

wordpress.org/plugins/express-pay-card

Описание

30 active installs v1.1.3 PHP 5.4+ WP 4.0+ Updated May 22, 2025
merchantonline-paymentpayment-gatewaypaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Экспресс Платежи: Интернет-Эквайринг Safe to Use in 2026?

Generally Safe

Score 100/100

Экспресс Платежи: Интернет-Эквайринг has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The express-pay-card plugin version 1.1.3 exhibits a generally positive security posture due to its limited attack surface and the absence of known vulnerabilities. The static analysis reveals no direct entry points like AJAX handlers, REST API routes, or shortcodes without authentication, which is a significant strength. The plugin also correctly utilizes prepared statements for its SQL queries and includes capability checks, demonstrating good coding practices.

However, concerns arise from the output escaping. With 47% of outputs properly escaped, there's a significant portion that is not. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed to users. Additionally, the taint analysis identified one flow with unsanitized paths, although it was not classified as critical or high severity. This, combined with the file operations, warrants further investigation to ensure these operations are secure and do not expose sensitive information or allow for unauthorized file modifications.

Given the complete lack of historical vulnerabilities, the plugin appears to be maintained with security in mind. However, the identified output escaping weakness and the taint flow involving unsanitized paths are areas that require immediate attention. While the plugin's current security is relatively strong due to its minimal attack surface and absence of direct exploits, these identified code-level concerns represent potential risks that could be exploited in the future if not addressed.

Key Concerns

  • Insufficient output escaping
  • Unsanitized paths in taint flow
Vulnerabilities
None known

Экспресс Платежи: Интернет-Эквайринг Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Экспресс Платежи: Интернет-Эквайринг Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-wc-gateway-expresspay-card> (includes\class-wc-gateway-expresspay-card.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Экспресс Платежи: Интернет-Эквайринг Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedwordpress_card_expresspay.php:37
filterwoocommerce_payment_gatewayswordpress_card_expresspay.php:38
actionwoocommerce_blocks_loadedwordpress_card_expresspay.php:39
actionbefore_woocommerce_initwordpress_card_expresspay.php:40
actionwoocommerce_blocks_payment_method_type_registrationwordpress_card_expresspay.php:103
Maintenance & Trust

Экспресс Платежи: Интернет-Эквайринг Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMay 22, 2025
PHP min version5.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Экспресс Платежи: Интернет-Эквайринг Developer Profile

Сервис "Экспресс Платежи"

3 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Экспресс Платежи: Интернет-Эквайринг

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/express-pay-card/assets/js/expresspay-card-checkout.js/wp-content/plugins/express-pay-card/assets/css/expresspay-card-checkout.css
Script Paths
/wp-content/plugins/express-pay-card/assets/js/expresspay-card-checkout.js
Version Parameters
expresspay-card-checkout.js?ver=expresspay-card-checkout.css?ver=

HTML / DOM Fingerprints

CSS Classes
expresspay-card-gateway-description
JS Globals
window.expressPayCard
FAQ

Frequently Asked Questions about Экспресс Платежи: Интернет-Эквайринг