
Gain Commerce NMI Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/gaincommerce-nmi-payment-gateway-for-woocommercePCI-compliant payment gateway integration between NMI and WooCommerce. Seamlessly accept e-commerce credit card payments through WooCommerce stores.
Is Gain Commerce NMI Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Gain Commerce NMI Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gaincommerce-nmi-payment-gateway-for-woocommerce" plugin, in version 1.12.0, exhibits a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns exist regarding its attack surface. The plugin exposes two AJAX handlers without any authentication checks, presenting a direct pathway for unauthenticated attackers to potentially interact with sensitive functionalities. Taint analysis results are notably absent, suggesting either a lack of comprehensive testing or no identified complex data flow vulnerabilities. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator, but it doesn't negate the risks identified in the static analysis. The primary weakness lies in the unprotected entry points, which could be exploited if the functionality they expose is not inherently secure or if data passed through them is not sufficiently validated and sanitized, despite the absence of identified taint flows.
Overall, the plugin has strengths in its database interaction and output handling. However, the presence of two unauthenticated AJAX endpoints is a critical security oversight. If these endpoints handle any user-supplied data or trigger actions that could impact the system's integrity or data, they represent a significant risk. The lack of recorded vulnerabilities in its history is positive, but proactive security measures, particularly robust authentication and authorization on all entry points, are crucial for mitigating the identified risks and maintaining a strong security posture.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without auth checks
Gain Commerce NMI Payment Gateway for WooCommerce Security Vulnerabilities
Gain Commerce NMI Payment Gateway for WooCommerce Code Analysis
Output Escaping
Gain Commerce NMI Payment Gateway for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
Gain Commerce NMI Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Gain Commerce NMI Payment Gateway for WooCommerce Alternatives
Pledged Plugins PCI Gateway for NMI and WooCommerce
wp-nmi-gateway-pci-woocommerce
PCI Compliant NMI payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
WP NMI Payment Gateway for WooCommerce
nmi-for-woocommerce
Integrate NMI with WooCommerce for secure, PCI-compliant payments. Accept credit cards and ACH for smooth WooCommerce transactions.
AM NMI Gateway for WooCommerce
am-nmi-gateway-for-woocommerce
The AM NMI Gateway for WooCommerce enables secure and efficient credit card payments via the NMI gateway.
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Asaas Gateway for WooCommerce
woo-asaas
Take transparent credit card and bank ticket payment checkouts on your store using Asaas.
Gain Commerce NMI Payment Gateway for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Gain Commerce NMI Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gaincommerce-nmi-payment-gateway-for-woocommerce/assets/js/ap-nmi-unified-integration.js/wp-content/plugins/gaincommerce-nmi-payment-gateway-for-woocommerce/assets/css/ap-nmi-unified-styles.csshttps://secure.nmi.com/token/Collect.jsgaincommerce-nmi-payment-gateway-for-woocommerce/assets/js/ap-nmi-unified-integration.js?ver=gaincommerce-nmi-payment-gateway-for-woocommerce/assets/css/ap-nmi-unified-styles.css?ver=nmi-collectjs?ver=HTML / DOM Fingerprints
data-tokenization-keyap_nmi_params