
iCard Checkout for WooCommerce Security & Risk Analysis
wordpress.org/plugins/icard-checkout-for-woocommerceA one-click checkout with a full range of payment services and regular settlement of funds
Is iCard Checkout for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100iCard Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "icard-checkout-for-woocommerce" v1.0.3 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, and a large attack surface are positive indicators. The plugin also demonstrates good practices in output escaping and nonce/capability checks, suggesting a developer conscious of common web security vulnerabilities.
However, there are specific areas for concern. The presence of a single SQL query that does not utilize prepared statements is a significant risk. Without prepared statements, this query is vulnerable to SQL injection attacks, especially if user-supplied data is directly incorporated into the query. Furthermore, while the attack surface is currently small, the plugin's reliance on external HTTP requests could introduce risks if those external services are compromised or if the plugin does not properly validate responses.
Overall, the plugin appears to be developed with security in mind, particularly concerning common WordPress attack vectors like XSS and CSRF. The lack of historical vulnerabilities further reinforces this. Nevertheless, the unparameterized SQL query is a critical flaw that needs immediate attention. Addressing this and ensuring robust validation of external HTTP requests would significantly improve the plugin's security.
Key Concerns
- Raw SQL query without prepared statements
iCard Checkout for WooCommerce Security Vulnerabilities
iCard Checkout for WooCommerce Release Timeline
iCard Checkout for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
iCard Checkout for WooCommerce Attack Surface
WordPress Hooks 12
Maintenance & Trust
iCard Checkout for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
iCard Checkout for WooCommerce Alternatives
MONEI Payments for WooCommerce
monei
Accept Card, Apple Pay, Google Pay, Bizum, PayPal and many more payment methods in your WooCommerce store using MONEI payment gateway.
KueskiPay Gateway
kueskipay-gateway
Add Kueski gateway to buy now and pay later on your store.
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Beanstream for WooCommerce
beanstream-gateway-for-woocommerce
A Payment Gateway for WooCommerce allowing you to take credit card payments using Beanstream.
uPress Payment Gateway
wc-upress-gw
uPress Payment Gateway is a simple plugin which allows any user to start receiving credit card payments in a couple of button clicks.
iCard Checkout for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect iCard Checkout for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/icard-checkout-for-woocommerce/assets/images/icard_logo.svgicard-checkout-for-woocommerce/woocommerce-gateway-icard.php?ver=icard-checkout-for-woocommerce/includes/class-wc-gateway-icard.php?ver=HTML / DOM Fingerprints
icard-ipg-overlaydata-payment-method-id="icard_checkout_woocommerce_integration"window.icard_checkout_woocommerce_integration/wp-json/icard_checkout_woocommerce/v1/webhook