Ingenico Server Integration Plugin Security & Risk Analysis

wordpress.org/plugins/ingenico-server-for-woocommerce

Plugin demonstrates a way to integrate Ingenico terminals with your WordPress/WooCommerce website. Ingenico fiscal terminals are widely used by eServi …

10 active installs v1.0.0 PHP 5.2.4+ WP 4.0+ Updated Nov 16, 2021
ingenicoinvoicepaymentterminalwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ingenico Server Integration Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Ingenico Server Integration Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "ingenico-server-for-woocommerce" v1.0.0 plugin exhibits a strong security posture based on the static analysis provided. It boasts a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. Crucially, all SQL queries are prepared, and there are no known historical vulnerabilities, suggesting a well-maintained and secure codebase.

However, a significant area for concern lies in the output escaping. With 37 total outputs and only 62% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals two flows with unsanitized paths, although these are not categorized as critical or high severity, they still represent potential security weaknesses. The complete absence of nonce and capability checks, while mitigated by the lack of an attack surface, is a notable oversight. If any entry points were to be introduced or discovered in future versions, this lack of basic security measures would become a critical vulnerability.

In conclusion, the plugin is currently in a good security state due to its limited attack surface and clean vulnerability history. The primary weakness is the insufficient output escaping, which needs immediate attention to prevent potential XSS attacks. The absence of nonce and capability checks is a less immediate but still important concern that should be addressed to ensure robust security if the plugin's exposed functionalities change.

Key Concerns

  • Unsanitized output found in 38% of cases
  • Unsanitized taint flows without severity
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Ingenico Server Integration Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ingenico Server Integration Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped37 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ingenico_server_for_woocommerce_page (ingenico-server-for-woocommerce.php:249)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ingenico Server Integration Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_headingenico-server-for-woocommerce.php:50
actionadmin_menuingenico-server-for-woocommerce.php:157
actionadmin_initingenico-server-for-woocommerce.php:543
Maintenance & Trust

Ingenico Server Integration Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 16, 2021
PHP min version5.2.4
Downloads804

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ingenico Server Integration Plugin Developer Profile

bigdotsoftware

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ingenico Server Integration Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ingenico-server-for-woocommerce/ingenico_server_for_woocommerce.php

HTML / DOM Fingerprints

CSS Classes
column-idcolumn-billingcolumn-date_createdcolumn-total
FAQ

Frequently Asked Questions about Ingenico Server Integration Plugin