GazChap's WooCommerce Purchase Order Payment Gateway Security & Risk Analysis

wordpress.org/plugins/gazchaps-woocommerce-purchase-order-payment-gateway

Adds a Purchase Order offline payment gateway to WooCommerce.

200 active installs v3.2 PHP 5.3+ WP 4.2.0+ Updated Nov 6, 2025
ecommercegatewaypaymentpurchase-orderwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GazChap's WooCommerce Purchase Order Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

GazChap's WooCommerce Purchase Order Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of gazchaps-woocommerce-purchase-order-payment-gateway v3.2 reveals a generally strong security posture. The plugin demonstrates excellent practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having a high percentage of properly escaped output. There are no file operations or external HTTP requests, which further limits potential attack vectors. The absence of any recorded vulnerabilities in its history is a significant positive indicator, suggesting a well-maintained and secure codebase. Furthermore, the plugin has a remarkably small attack surface, with zero identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events, especially noteworthy is that none of these potential entry points are left unprotected. A minor concern arises from the complete absence of nonce and capability checks, which, while not immediately exploitable due to the lack of entry points, is a deviation from best practices for securing any potential future additions or unexpected pathways. Despite this minor point, the plugin exhibits strong security hygiene.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

GazChap's WooCommerce Purchase Order Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GazChap's WooCommerce Purchase Order Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
49 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped57 total outputs
Attack Surface

GazChap's WooCommerce Purchase Order Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_enqueue_scriptsclass.admin.php:9
actionwoocommerce_admin_order_data_after_billing_addressclass.admin.php:10
actionwoocommerce_admin_order_data_after_billing_addressclass.admin.php:11
actionwoocommerce_process_shop_order_metaclass.admin.php:12
actionwoocommerce_email_after_order_tableclass.gateway.php:48
actionwoocommerce_email_after_order_tableclass.gateway.php:51
actionwoocommerce_email_after_order_tableclass.gateway.php:55
actionplugins_loadedindex.php:31
actionplugins_loadedindex.php:32
actionadmin_initindex.php:34
filterwoocommerce_payment_gatewaysindex.php:35
actionrest_api_initindex.php:38
actionbefore_woocommerce_initindex.php:41
actionadmin_noticesindex.php:66
Maintenance & Trust

GazChap's WooCommerce Purchase Order Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 6, 2025
PHP min version5.3
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs200
Developer Profile

GazChap's WooCommerce Purchase Order Payment Gateway Developer Profile

gazchap

2 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GazChap's WooCommerce Purchase Order Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gazchaps-woocommerce-purchase-order-payment-gateway/admin.min.css/wp-content/plugins/gazchaps-woocommerce-purchase-order-payment-gateway/admin.min.js
Script Paths
/wp-content/plugins/gazchaps-woocommerce-purchase-order-payment-gateway/admin.min.js
Version Parameters
gazchaps-woocommerce-purchase-order-payment-gateway/admin.min.js?ver=gazchaps-woocommerce-purchase-order-payment-gateway/admin.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
gazchap_purchase_order_fields
JS Globals
gcWcPoPg
REST Endpoints
/wp-json/wp/v2/shop_order/gazchap_purchase_order_number/wp-json/wp/v2/shop_order/gazchap_purchase_order_address
FAQ

Frequently Asked Questions about GazChap's WooCommerce Purchase Order Payment Gateway