GoDaddy Payments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/godaddy-payments

A payment gateway plugin that enables your U.S. or Canadian business to accept credit card payments directly on your WooCommerce site.

1K active installs v1.7.7 PHP 7.4+ WP 5.6+ Updated Jan 26, 2026
checkoutcredit-carde-commerceecommercepayments
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GoDaddy Payments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

GoDaddy Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "godaddy-payments" plugin v1.7.7 exhibits a generally strong security posture based on the provided static analysis. There are no critical or high-severity code signals, no taint analysis findings, and a clean vulnerability history. The plugin demonstrates good practices such as proper output escaping for the vast majority of outputs, the presence of nonce and capability checks, and a minimal attack surface. The absence of known CVEs further contributes to its positive security standing.

However, there are a few areas that warrant attention. The plugin utilizes raw SQL queries without prepared statements for both identified SQL operations, which introduces a risk of SQL injection, especially if the data used in these queries originates from user input. Additionally, while the overall attack surface is small, the presence of a shortcode without explicit mention of an authorization check is a minor concern. The limited scope of the static analysis, particularly the zero taint flows analyzed, means that potential vulnerabilities might remain undetected if more complex data flows were involved.

In conclusion, "godaddy-payments" v1.7.7 appears to be a reasonably secure plugin with a history of no reported vulnerabilities. The main security concern lies with the unparameterized SQL queries. While the plugin has strengths in its limited attack surface and good output escaping, the raw SQL usage is a clear area for improvement to mitigate potential risks.

Key Concerns

  • Raw SQL queries without prepared statements
  • Shortcode without explicit auth check mentioned
Vulnerabilities
None known

GoDaddy Payments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GoDaddy Payments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
14
59 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

81% escaped73 total outputs
Attack Surface

GoDaddy Payments for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fee] src\Shipping\LocalDelivery\LocalDelivery.php:308
WordPress Hooks 41
actionadmin_initgodaddy-payments.php:57
actionadmin_initgodaddy-payments.php:58
actionadmin_noticesgodaddy-payments.php:60
filterextra_plugin_headersgodaddy-payments.php:62
actionplugins_loadedgodaddy-payments.php:66
filterwoocommerce_email_classessrc\Emails\Emails.php:37
actionadmin_initsrc\Frontend\Admin\Notices.php:300
actionadmin_noticessrc\Frontend\Admin\Notices.php:301
filterwoocommerce_order_fully_refunded_statussrc\Gateways\CreditCardGateway.php:177
actionadmin_enqueue_scriptssrc\Gateways\PayInPersonGateway.php:113
actionwoocommerce_email_before_order_tablesrc\Gateways\PayInPersonGateway.php:116
actionadmin_initsrc\Lifecycle.php:57
actionwoocommerce_order_details_before_order_table_itemssrc\Pages\ViewOrderPage.php:40
actionadmin_enqueue_scriptssrc\Payments\Captures.php:52
actionwoocommerce_order_item_add_action_buttonssrc\Payments\Captures.php:54
actionadmin_enqueue_scriptssrc\Plugin.php:124
actionadmin_enqueue_scriptssrc\Plugin.php:125
actionwp_enqueue_scriptssrc\Plugin.php:126
filterwoocommerce_shipping_methodssrc\Shipping\CoreShippingMethods.php:47
filterwoocommerce_get_order_item_totalssrc\Shipping\CoreShippingMethods.php:48
actionwoocommerce_after_shipping_ratesrc\Shipping\CoreShippingMethods.php:50
filterwoocommerce_email_classessrc\Shipping\LocalPickup\Emails.php:38
filterwoocommerce_shipping_instance_form_fields_local_pickupsrc\Shipping\LocalPickup\LocalPickup.php:48
actionwoocommerce_after_shipping_ratesrc\Shipping\LocalPickup\LocalPickup.php:49
actionwoocommerce_email_customer_detailssrc\Shipping\LocalPickup\LocalPickup.php:50
actionwoocommerce_thankyousrc\Shipping\LocalPickup\LocalPickup.php:51
actionadmin_enqueue_scriptssrc\Support\Client.php:50
actionadmin_footersrc\Support\Client.php:51
actionadmin_initsrc\Sync\Jobs\ActiveSmartTerminalDetector.php:48
actionwoocommerce_thankyousrc\Sync\PoyntOrderSynchronizer.php:55
actionwoocommerce_new_ordersrc\Sync\PoyntOrderSynchronizer.php:56
actionwoocommerce_update_ordersrc\Sync\PoyntOrderSynchronizer.php:57
actionwoocommerce_order_status_completedsrc\Sync\PoyntOrderSynchronizer.php:59
actionwoocommerce_order_status_cancelledsrc\Sync\PoyntOrderSynchronizer.php:60
actionwoocommerce_refund_createdsrc\Sync\PoyntOrderSynchronizer.php:63
actionwoocommerce_create_refundsrc\Sync\PoyntOrderSynchronizer.php:64
filterwoocommerce_order_get_payment_methodsrc\Sync\PoyntOrderSynchronizer.php:101
filterwoocommerce_order_get_payment_methodsrc\Webhooks\PoyntTransactionWebhookHandler.php:170
filterwc_poynt_refund_request_datasrc\Webhooks\PoyntTransactionWebhookHandler.php:189
filterwc_poynt_void_request_datasrc\Webhooks\PoyntTransactionWebhookHandler.php:221
actionwoocommerce_api_poyntsrc\Webhooks\PoyntWebhooksHandler.php:50
Maintenance & Trust

GoDaddy Payments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version7.4
Downloads42K

Community Trust

Rating86/100
Number of ratings6
Active installs1K
Developer Profile

GoDaddy Payments for WooCommerce Developer Profile

GoDaddy

5 plugins · 364K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect GoDaddy Payments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/godaddy-payments/vendor/skyverge/wc-plugin-framework/woocommerce/class-sv-wc-plugin.php/wp-content/plugins/godaddy-payments/vendor/skyverge/wc-plugin-framework/woocommerce/payment-gateway/class-sv-wc-payment-gateway-plugin.php/wp-content/plugins/godaddy-payments/src/Functions.php

HTML / DOM Fingerprints

JS Globals
poynt_for_woocommerce
FAQ

Frequently Asked Questions about GoDaddy Payments for WooCommerce