GarantiBBVA Payment Gateway Security & Risk Analysis

wordpress.org/plugins/garanti-payment-gateway-for-woocommerce

GarantiBBVA is a payment gateway integration plugin that provides secure and easy payment solution developed for WooCommerce.

200 active installs v2.1.0 PHP 7.4+ WP 5.8+ Updated Dec 23, 2025
odemeucretsizeticsoftsanal-poswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GarantiBBVA Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

GarantiBBVA Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "garanti-payment-gateway-for-woocommerce" plugin version 2.1.0 exhibits a strong security posture. The code analysis reveals a minimal attack surface with only two AJAX handlers, and importantly, both are protected by authentication checks. The plugin effectively utilizes prepared statements for all SQL queries, demonstrates excellent output escaping with only a small percentage of outputs unescaped, and implements nonce and capability checks where appropriate. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. The plugin also has a clean vulnerability history, with no known CVEs recorded, indicating a commitment to security by the developers or a lack of past exploitable issues.

While the overall security is commendable, the presence of any unescaped output, even at 7%, represents a potential minor risk for cross-site scripting (XSS) vulnerabilities if the unescaped data originates from user input or external sources. However, given the low percentage and the lack of known vulnerabilities, this risk appears to be minimal in practice. The absence of taint analysis results with unsanitized paths is also a positive sign, suggesting that any potential data flow issues were either not detected or are effectively mitigated by the existing code. In conclusion, this plugin appears to be well-secured and a low risk for most WordPress sites, with only a very minor concern regarding the small amount of unescaped output.

Key Concerns

  • Minor percentage of unescaped output
Vulnerabilities
None known

GarantiBBVA Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GarantiBBVA Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
53 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped57 total outputs
Attack Surface

GarantiBBVA Payment Gateway Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_gbbva_internal_api_requestgarantibbva.php:46
noprivwp_ajax_gbbva_internal_api_requestgarantibbva.php:47
WordPress Hooks 16
actionadmin_menuadmin\class-admin.php:10
actionadmin_enqueue_scriptsadmin\class-admin.php:12
filterscript_loader_tagadmin\class-admin.php:104
actionplugins_loadedgarantibbva.php:42
actionplugins_loadedgarantibbva.php:43
actionplugins_loadedgarantibbva.php:44
actionwp_footergarantibbva.php:45
actionwp_enqueue_scriptsgarantibbva.php:48
actionadmin_enqueue_scriptsgarantibbva.php:49
actionadmin_noticesgarantibbva.php:92
actionadmin_footergarantibbva.php:102
actionwp_enqueue_scriptsgarantibbva.php:265
filterwp_kses_allowed_htmlgarantibbva.php:267
actionwoocommerce_admin_order_data_after_billing_addressgarantibbva.php:272
filterwoocommerce_product_tabsgarantibbva.php:593
filterwoocommerce_payment_gatewaysgarantibbva.php:643
Maintenance & Trust

GarantiBBVA Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 23, 2025
PHP min version7.4
Downloads4K

Community Trust

Rating20/100
Number of ratings1
Active installs200
Developer Profile

GarantiBBVA Payment Gateway Developer Profile

garantieticaret

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GarantiBBVA Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/garanti-payment-gateway-for-woocommerce/assets/css/admin-popup.css/wp-content/plugins/garanti-payment-gateway-for-woocommerce/assets/js/admin-popup.js
Version Parameters
garanti-payment-gateway-for-woocommerce?ver=2.1.0

HTML / DOM Fingerprints

CSS Classes
gbbva-noticegbbva-popup-overlaygbbva-popupgbbva-popup-contentgbbva-popup-closegbbva-popup-title
Data Attributes
id="gbbva-show-instructions"
JS Globals
window.gbbva_checkout_settingswindow.gbbva_checkout_params
REST Endpoints
/wp-json/garantibbva/v1/get-currency
FAQ

Frequently Asked Questions about GarantiBBVA Payment Gateway