HNB bank payment gateway Security & Risk Analysis

wordpress.org/plugins/hnb-payment-gateway

WooCormace HNB bank payment gateway. Make you'r online payments via HNB bank.

10 active installs v1.2 PHP + WP 3.9+ Updated Jan 19, 2017
hnbhnb-bankhnb-bank-srilankapayment-gatewaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HNB bank payment gateway Safe to Use in 2026?

Generally Safe

Score 85/100

HNB bank payment gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "hnb-payment-gateway" plugin v1.2 exhibits a generally concerning security posture due to a lack of fundamental security practices, despite the absence of known vulnerabilities or critical taint flows. The static analysis reveals a complete absence of any authorization checks for its limited entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, the plugin fails to implement proper output escaping, with 0% of its identified outputs being sanitized. This combination of unauthenticated entry points and unsanitized output creates a significant risk of various injection attacks, such as cross-site scripting (XSS) if any output is rendered to the user without proper encoding. The presence of a single SQL query that does not use prepared statements, while minor in isolation, adds another layer of potential risk for SQL injection, especially in conjunction with unsanitized input. The vulnerability history showing no past issues is a positive indicator, but it does not mitigate the risks identified in the current code analysis. Overall, while the attack surface and taint analysis are clean, the core security implementation is severely lacking, making the plugin vulnerable to common web attacks.

Key Concerns

  • No authorization checks on entry points
  • No output escaping
  • SQL query not using prepared statements
Vulnerabilities
None known

HNB bank payment gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

HNB bank payment gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped5 total outputs
Attack Surface

HNB bank payment gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedhnb-payment-gateway-woocommerce.php:12
actioninithnb-payment-gateway-woocommerce.php:50
actionwoocommerce_update_options_payment_gatewayshnb-payment-gateway-woocommerce.php:55
actionwoocommerce_receipt_HNBIPGhnb-payment-gateway-woocommerce.php:57
filterwoocommerce_payment_gatewayshnb-payment-gateway-woocommerce.php:371
Maintenance & Trust

HNB bank payment gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJan 19, 2017
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

HNB bank payment gateway Developer Profile

Oganro

8 plugins · 190 total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HNB bank payment gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hnb-payment-gateway/hnb.jpg

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about HNB bank payment gateway