
Float Payment Gateway Security & Risk Analysis
wordpress.org/plugins/float-gatewayTake credit card payments on your store using the Float API.
Is Float Payment Gateway Safe to Use in 2026?
Generally Safe
Score 99/100Float Payment Gateway has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "float-gateway" v1.1.11 exhibits a mixed security posture. While static analysis reveals a generally clean codebase with proper SQL statement preparation and a high percentage of output escaping, there are significant concerns regarding authorization checks and a history of vulnerabilities. The absence of nonce checks and capability checks on entry points like AJAX handlers and shortcodes is a critical oversight, leaving these areas susceptible to cross-site request forgery (CSRF) and unauthorized access if not properly protected by the WordPress core or other plugins.
The vulnerability history, specifically a medium-severity "Incorrect Authorization" vulnerability, further highlights these authorization weaknesses. The fact that this vulnerability is now patched is positive, but the pattern suggests a recurring area of concern that requires careful monitoring and robust implementation of WordPress security best practices. The plugin's limited attack surface and reliance on external HTTP requests, while not inherently a vulnerability, could be an indirect vector if those external services have security flaws.
In conclusion, "float-gateway" has strengths in its data handling and output sanitization. However, the identified gaps in authorization checks on its entry points and the past vulnerability type are significant weaknesses that require attention. The plugin is not inherently insecure due to the static analysis results, but the potential for exploitation due to missing authorization controls and its historical vulnerability pattern warrants a cautious approach.
Key Concerns
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
- Missing capability checks on shortcodes
- Past medium severity authorization vulnerability
Float Payment Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Float Payment Gateway <= 1.1.9 - Improper Authorization to Unauthenticated Order Status Manipulation
Float Payment Gateway Code Analysis
Output Escaping
Float Payment Gateway Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Float Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Float Payment Gateway Alternatives
Side Cart Woocommerce | Woocommerce Cart
side-cart-woocommerce
Manage your cart from just a click away with an interactive design
Sliding Cart for WooCommerce by FunnelKit – Skip Cart & Reach WooCommerce Checkout Faster
cart-for-woocommerce
FunnelKit Cart adds a beautiful sliding cart to your WooCommerce store. Let the buyers add items, edit quantity and add upsells on the side cart.
Modern Cart – WooCommerce Side Cart & Popup Cart
modern-cart
Modern Cart gives your store a side cart and free shipping bar so shoppers stay on the page, spend more to unlock rewards, and check out in seconds.
WPC Fly Cart for WooCommerce
woo-fly-cart
WPC Fly Cart is an interactive mini cart for WooCommerce. It allows users to update product quantities or remove products without reloading the page.
Advance Side Cart, Ajax Cart & Floating Cart for WooCommerce
th-all-in-one-woo-cart
Enhance your Cart for WooCommerce with a modern side cart and floating cart. Improve shopping experience with a fast, Ajax-powered shopping cart.
Float Payment Gateway Developer Profile
1 plugin · 100 total installs
How We Detect Float Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/float-gateway/assets/css/float.css/wp-content/plugins/float-gateway/assets/js/featherlite.js/wp-content/plugins/float-gateway/assets/js/featherlite.jsfloat-gateway/assets/css/float.css?ver=float-gateway/assets/js/featherlite.js?ver=HTML / DOM Fingerprints
float-gateway-payment-formFloat Payment Gateway© FLOAT TECHNOLOGIES (PTY) LTDInitialize plugin bootstrap class.Register Float Gateway+12 moredata-float-gateway-iddata-float-gateway-client-iddata-float-gateway-merchant-idreadonly='readonly'FloatGatewayfloat_gateway_paramsfeatherlight/wp-json/wc-float/v1/payment/wc-float/v1/payment