FLIZpay Gateway für WooCommerce Security & Risk Analysis

wordpress.org/plugins/flizpay-for-woocommerce

Mit dem FLIZpay-Plugin kannst du die Zahlungsmethode FLIZ in deinen Checkout integrieren. FLIZ ist für Shops und Zahlende gebührenfrei.

100 active installs v2.4.17 PHP 7.0+ WP 4.4+ Updated Feb 19, 2026
cashbackkostenlosno-feepaymentszahlung
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FLIZpay Gateway für WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

FLIZpay Gateway für WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "flizpay-for-woocommerce" plugin version 2.4.17 exhibits a generally good security posture, with several positive indicators. The complete absence of known CVEs and a history of no recorded vulnerabilities suggest a diligent approach to security by the developers. Furthermore, the plugin demonstrates strong practices in SQL query handling, with 100% using prepared statements, and excellent output escaping, with 97% of outputs properly escaped. The use of bundled libraries like Guzzle is noted, though their specific version and patch status are not detailed here.

However, there are some areas of concern that warrant attention. The plugin has a total of 4 AJAX handlers, with 2 of them lacking proper authentication checks. This presents a potential attack vector where unauthorized users might be able to trigger sensitive actions. While the static analysis did not reveal any dangerous functions or critical taint analysis findings, the presence of unprotected AJAX endpoints is a notable weakness that could be exploited if they perform sensitive operations.

In conclusion, the plugin benefits from a clean vulnerability history and good practices in common security areas. The primary weakness lies in the unprotected AJAX endpoints, which require careful review and potentially the addition of nonce and capability checks to mitigate risk. Addressing these specific entry points would significantly strengthen the plugin's overall security.

Key Concerns

  • AJAX handlers without auth checks
Vulnerabilities
None known

FLIZpay Gateway für WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FLIZpay Gateway für WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
38 escaped
Nonce Checks
3
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

97% escaped39 total outputs
Attack Surface
2 unprotected

FLIZpay Gateway für WooCommerce Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_flizpay_express_checkoutincludes\class-flizpay-gateway.php:108
noprivwp_ajax_flizpay_express_checkoutincludes\class-flizpay-gateway.php:109
authwp_ajax_flizpay_order_finishincludes\class-flizpay.php:224
noprivwp_ajax_flizpay_order_finishincludes\class-flizpay.php:225
WordPress Hooks 20
actionplugins_loadedflizpay.php:63
actionadmin_noticesflizpay.php:70
actionadmin_noticesflizpay.php:81
actionadmin_initflizpay.php:86
actionupgrader_process_completeflizpay.php:131
filterwoocommerce_payment_gatewaysflizpay.php:160
actionplugins_loadedincludes\class-flizpay-gateway.php:9
actionwoocommerce_settings_save_checkoutincludes\class-flizpay-gateway.php:97
actioninitincludes\class-flizpay-gateway.php:100
actiontemplate_redirectincludes\class-flizpay-gateway.php:101
filterwoocommerce_email_enabled_new_orderincludes\class-flizpay-gateway.php:104
actioninitincludes\class-flizpay.php:183
actionadmin_enqueue_scriptsincludes\class-flizpay.php:199
actionadmin_enqueue_scriptsincludes\class-flizpay.php:200
filterflizpay_load_settingsincludes\class-flizpay.php:201
actionbefore_woocommerce_initincludes\class-flizpay.php:218
actionwoocommerce_blocks_loadedincludes\class-flizpay.php:220
actionwp_enqueue_scriptsincludes\class-flizpay.php:222
actionwp_enqueue_scriptsincludes\class-flizpay.php:223
actionwoocommerce_blocks_payment_method_type_registrationpublic\class-flizpay-public.php:222
Maintenance & Trust

FLIZpay Gateway für WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 19, 2026
PHP min version7.0
Downloads6K

Community Trust

Rating80/100
Number of ratings2
Active installs100
Developer Profile

FLIZpay Gateway für WooCommerce Developer Profile

FLIZpay

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FLIZpay Gateway für WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flizpay-for-woocommerce/css/flizpay-admin.css/wp-content/plugins/flizpay-for-woocommerce/js/flizpay-admin.js
Version Parameters
flizpay-for-woocommerce/css/flizpay-admin.css?ver=flizpay-for-woocommerce/js/flizpay-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
flizpay-settings-section
HTML Comments
<!-- FLIZpay Express Checkout --><!-- End FLIZpay Express Checkout --><!-- FLIZPAY Settings -->
Data Attributes
data-flizpay-countrydata-flizpay-placeholderdata-flizpay-typedata-flizpay-modal-triggerdata-flizpay-express-checkout-enabled
JS Globals
flizpayParams
FAQ

Frequently Asked Questions about FLIZpay Gateway für WooCommerce