Gale HSA & FSA Payments Security & Risk Analysis

wordpress.org/plugins/gale-hsa-fsa-payments

Gale Payments enables WooCommerce stores to accept HSA/FSA payments

20 active installs v1.0.14 PHP 7.2+ WP 5.0+ Updated Aug 15, 2025
fsahealthcarehsapaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gale HSA & FSA Payments Safe to Use in 2026?

Generally Safe

Score 100/100

Gale HSA & FSA Payments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "gale-hsa-fsa-payments" plugin v1.0.14 exhibits a generally good security posture, with several strengths observed in its static analysis. The absence of dangerous functions, raw SQL queries, and file operations are positive indicators. The high percentage of properly escaped output and the presence of nonce checks suggest an effort to mitigate common web vulnerabilities. Furthermore, the plugin has no recorded history of known vulnerabilities (CVEs), which is a strong sign of stability and a well-maintained codebase.

However, there are a few areas that warrant attention and present potential risks. The presence of 3 REST API routes, with one lacking permission callbacks, represents a significant security concern. This unprotected entry point could be exploited by unauthenticated users to interact with the plugin's functionality, potentially leading to unauthorized actions or data manipulation. The plugin also makes 5 external HTTP requests, which, while not inherently insecure, could become a vector for vulnerabilities if the remote services are compromised or if the requests are not handled securely.

In conclusion, while the plugin demonstrates good security practices in many areas and has a clean vulnerability history, the unprotected REST API route is a critical weakness that needs immediate remediation. The external HTTP requests also present a potential, albeit lower, risk. Addressing the unprotected REST API endpoint is paramount to improving the plugin's overall security.

Key Concerns

  • REST API route without permission callbacks
  • External HTTP requests
Vulnerabilities
None known

Gale HSA & FSA Payments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gale HSA & FSA Payments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
55 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

96% escaped57 total outputs
Attack Surface
1 unprotected

Gale HSA & FSA Payments Attack Surface

Entry Points5
Unprotected1

REST API Routes 3

POST/wp-json/gale-checkout/v1/update-order-statusincludes\class-with-gale-rest-api.php:13
POST/wp-json/gale-checkout/v1/update-productincludes\class-with-gale-rest-api.php:20
GET/wp-json/gale-checkout/v1/products-eligibilityincludes\class-with-gale-rest-api.php:27

Shortcodes 2

[gale_hsa_fsa_ts_product_widget] includes\class-gale-hsa-fsa-ts-checkout.php:36
[gale_hsa_fsa_ts_medical_widget] includes\class-gale-hsa-fsa-ts-checkout.php:37
WordPress Hooks 17
actionadmin_noticesgale-hsa-fsa-payments.php:35
actionwoocommerce_blocks_payment_method_type_registrationgale-hsa-fsa-payments.php:49
actionplugins_loadedgale-hsa-fsa-payments.php:54
actionadmin_noticesgale-hsa-fsa-payments.php:69
filterwoocommerce_payment_gatewaysgale-hsa-fsa-payments.php:76
actionwoocommerce_product_options_general_product_datagale-hsa-fsa-payments.php:83
actionwoocommerce_process_product_metagale-hsa-fsa-payments.php:84
actionadmin_menugale-hsa-fsa-payments.php:85
actionwoocommerce_update_productgale-hsa-fsa-payments.php:86
actiontransition_post_statusgale-hsa-fsa-payments.php:87
actionplugins_loadedgale-hsa-fsa-payments.php:89
actionwoocommerce_update_productgale-hsa-fsa-payments.php:129
actionadmin_enqueue_scriptsgale-hsa-fsa-payments.php:401
actionadmin_noticesgale-hsa-fsa-payments.php:464
actiongale_sync_batchgale-hsa-fsa-payments.php:582
actionwp_enqueue_scriptsincludes\class-gale-hsa-fsa-ts-checkout.php:33
actionrest_api_initincludes\class-with-gale-rest-api.php:9
Maintenance & Trust

Gale HSA & FSA Payments Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedAug 15, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Gale HSA & FSA Payments Developer Profile

Qadeer

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gale HSA & FSA Payments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gale-hsa-fsa-payments/assets/js/gale-hsa-fsa-ts-admin.js/wp-content/plugins/gale-hsa-fsa-payments/assets/css/gale-hsa-fsa-ts-admin.css/wp-content/plugins/gale-hsa-fsa-payments/assets/js/gale-hsa-fsa-ts.js
Script Paths
/wp-content/plugins/gale-hsa-fsa-payments/assets/js/gale-hsa-fsa-ts-admin.js/wp-content/plugins/gale-hsa-fsa-payments/assets/js/gale-hsa-fsa-ts.js
Version Parameters
gale-hsa-fsa-payments/assets/js/gale-hsa-fsa-ts-admin.js?ver=gale-hsa-fsa-payments/assets/css/gale-hsa-fsa-ts-admin.css?ver=gale-hsa-fsa-payments/assets/js/gale-hsa-fsa-ts.js?ver=

HTML / DOM Fingerprints

CSS Classes
gale_product_eligibility_fieldgale_product_eligibility_label
HTML Comments
<!-- Start of Gale HSA/FSA Payment Gateway Section --><!-- End of Gale HSA/FSA Payment Gateway Section -->
Data Attributes
data-gale-product-iddata-gale-eligibility
JS Globals
gale_hsa_fsa_ts_ajax_objectGalePaymentProcessor
REST Endpoints
/wp-json/gale-hsa-fsa-payments/v1/products/wp-json/gale-hsa-fsa-payments/v1/webhook
FAQ

Frequently Asked Questions about Gale HSA & FSA Payments