Gateway Coupon Assistant Security & Risk Analysis

wordpress.org/plugins/gateway-coupon-assistant

Create and manage WooCommerce coupons that are only valid for specific payment gateways. Display promotional banners to boost sales.

20 active installs v1.2.0 PHP 7.4+ WP + Updated Oct 20, 2025
conditional-coupongateway-specific-discountmarketingpayment-gateway-couponwoocommerce-discount
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gateway Coupon Assistant Safe to Use in 2026?

Generally Safe

Score 100/100

Gateway Coupon Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The gateway-coupon-assistant plugin v1.2.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, file operations, and external HTTP requests is a significant positive indicator. All SQL queries are properly prepared, and output escaping is nearly perfect, minimizing the risk of common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The presence of nonce checks on all AJAX handlers further strengthens its defenses against CSRF attacks.

However, a notable area for improvement is the lack of capability checks on its AJAX handlers. While nonce checks are in place, this does not inherently prevent authenticated users from performing actions they shouldn't have permission for. The attack surface, though small with only two AJAX entry points, could be further hardened by implementing role-based access control. The plugin's history of zero known CVEs is commendable and suggests a proactive approach to security by its developers.

In conclusion, gateway-coupon-assistant v1.2.0 is generally secure, with its developers adhering to many best practices. The primary concern is the absence of capability checks on AJAX handlers, which represents a minor but addressable security gap. The plugin's clean vulnerability history and robust handling of SQL and output indicate a well-maintained codebase.

Key Concerns

  • AJAX handlers missing capability checks
Vulnerabilities
None known

Gateway Coupon Assistant Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gateway Coupon Assistant Release Timeline

v1.2.0Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Gateway Coupon Assistant Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
57 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped58 total outputs
Attack Surface

Gateway Coupon Assistant Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_gwcpa_apply_couponincludes\class-gwcpa-frontend.php:14
noprivwp_ajax_gwcpa_apply_couponincludes\class-gwcpa-frontend.php:15
WordPress Hooks 15
actionadmin_noticesgateway-coupon-assistant.php:25
actionplugins_loadedgateway-coupon-assistant.php:35
filterwoocommerce_coupon_data_tabsincludes\class-gwcpa-admin.php:7
actionwoocommerce_coupon_data_panelsincludes\class-gwcpa-admin.php:8
actionwoocommerce_process_shop_coupon_metaincludes\class-gwcpa-admin.php:9
actionadmin_menuincludes\class-gwcpa-admin.php:10
actionadmin_initincludes\class-gwcpa-admin.php:11
actionadmin_enqueue_scriptsincludes\class-gwcpa-admin.php:12
filterwoocommerce_coupon_is_validincludes\class-gwcpa-frontend.php:7
actionwoocommerce_before_calculate_totalsincludes\class-gwcpa-frontend.php:8
filterwoocommerce_coupon_get_discount_amountincludes\class-gwcpa-frontend.php:9
actionwoocommerce_review_order_before_paymentincludes\class-gwcpa-frontend.php:10
actionwoocommerce_before_checkout_formincludes\class-gwcpa-frontend.php:11
actionwoocommerce_before_cart_totalsincludes\class-gwcpa-frontend.php:12
actionwp_enqueue_scriptsincludes\class-gwcpa-frontend.php:13
Maintenance & Trust

Gateway Coupon Assistant Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 20, 2025
PHP min version7.4
Downloads368

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Gateway Coupon Assistant Developer Profile

amin hosseini

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gateway Coupon Assistant

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gateway-coupon-assistant/assets/css/admin-style.css/wp-content/plugins/gateway-coupon-assistant/assets/js/admin-script.js
Script Paths
/wp-content/plugins/gateway-coupon-assistant/assets/js/admin-script.js
Version Parameters
gateway-coupon-assistant/assets/css/admin-style.css?ver=gateway-coupon-assistant/assets/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
gwcpa_coupon_datagwcpa_discount_cap_wrappercyg-settings-wrap
HTML Comments
<!-- Provided by Gateway Coupon Assistant -->
Data Attributes
data-placeholder
JS Globals
gwcpa_admin_params
FAQ

Frequently Asked Questions about Gateway Coupon Assistant