iCard Checkout for WooCommerce Security & Risk Analysis

wordpress.org/plugins/icard-checkout-for-woocommerce

A one-click checkout with a full range of payment services and regular settlement of funds

0 active installs v1.0.3 PHP 7.4+ WP 6.8+ Updated Feb 16, 2026
credit-carde-commerceecommercepayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is iCard Checkout for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

iCard Checkout for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "icard-checkout-for-woocommerce" v1.0.3 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, and a large attack surface are positive indicators. The plugin also demonstrates good practices in output escaping and nonce/capability checks, suggesting a developer conscious of common web security vulnerabilities.

However, there are specific areas for concern. The presence of a single SQL query that does not utilize prepared statements is a significant risk. Without prepared statements, this query is vulnerable to SQL injection attacks, especially if user-supplied data is directly incorporated into the query. Furthermore, while the attack surface is currently small, the plugin's reliance on external HTTP requests could introduce risks if those external services are compromised or if the plugin does not properly validate responses.

Overall, the plugin appears to be developed with security in mind, particularly concerning common WordPress attack vectors like XSS and CSRF. The lack of historical vulnerabilities further reinforces this. Nevertheless, the unparameterized SQL query is a critical flaw that needs immediate attention. Addressing this and ensuring robust validation of external HTTP requests would significantly improve the plugin's security.

Key Concerns

  • Raw SQL query without prepared statements
Vulnerabilities
None known

iCard Checkout for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

iCard Checkout for WooCommerce Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

iCard Checkout for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
1
29 escaped
Nonce Checks
4
Capability Checks
3
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

97% escaped30 total outputs
Attack Surface

iCard Checkout for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitincludes\class-icard-install.php:15
actionicard_checkout_woocommerce_verify_notifyincludes\class-wc-gateway-icard.php:92
actionicard_checkout_woocommerce_verify_notify_postincludes\class-wc-gateway-icard.php:93
actionwoocommerce_before_cartincludes\class-wc-gateway-icard.php:94
actionwoocommerce_before_checkout_formincludes\class-wc-gateway-icard.php:95
actionwp_loadedincludes\class-wc-gateway-icard.php:96
actionplugins_loadedwoocommerce-gateway-icard.php:50
filterwoocommerce_payment_gatewayswoocommerce-gateway-icard.php:51
actionwoocommerce_blocks_loadedwoocommerce-gateway-icard.php:52
actionwp_enqueue_scriptswoocommerce-gateway-icard.php:53
actionwoocommerce_blocks_payment_method_type_registrationwoocommerce-gateway-icard.php:73
filter__experimental_woocommerce_blocks_add_data_attributes_to_blockwoocommerce-gateway-icard.php:83
Maintenance & Trust

iCard Checkout for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 16, 2026
PHP min version7.4
Downloads505

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

iCard Checkout for WooCommerce Developer Profile

iCard

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect iCard Checkout for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/icard-checkout-for-woocommerce/assets/images/icard_logo.svg
Version Parameters
icard-checkout-for-woocommerce/woocommerce-gateway-icard.php?ver=icard-checkout-for-woocommerce/includes/class-wc-gateway-icard.php?ver=

HTML / DOM Fingerprints

CSS Classes
icard-ipg-overlay
Data Attributes
data-payment-method-id="icard_checkout_woocommerce_integration"
JS Globals
window.icard_checkout_woocommerce_integration
REST Endpoints
/wp-json/icard_checkout_woocommerce/v1/webhook
FAQ

Frequently Asked Questions about iCard Checkout for WooCommerce