IranDargah Payment Gateway for Woocommerce Security & Risk Analysis

wordpress.org/plugins/irandargah-payment-gateway-for-woocommerce

پرداخت اینترنتی وجه به وسیله درگاه پرداخت ایران درگاه برای افزونه ووکامرس

500 active installs v2.3 PHP 7.4+ WP 6.2+ Updated Feb 8, 2026
gatewayirandargahpaymentwoocommerce%d8%a7%db%8c%d8%b1%d8%a7%d9%86-%d8%af%d8%b1%da%af%d8%a7%d9%87
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IranDargah Payment Gateway for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

IranDargah Payment Gateway for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "irandargah-payment-gateway-for-woocommerce" plugin v2.3 exhibits a generally positive security posture based on the static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the use of prepared statements for all SQL queries and a high percentage of properly escaped output are excellent security practices.

However, there are a few areas of concern. The presence of two "flows with unsanitized paths" in the taint analysis, even without critical or high severity, indicates potential for issues if user input is not properly handled downstream. The single external HTTP request also warrants attention, as it could be a vector for further attacks if the external endpoint is compromised or if data sent to it is not adequately secured.

Despite the lack of recorded vulnerabilities or CVEs, the plugin's security is not entirely guaranteed due to the identified unsanitized paths. The absence of vulnerability history might indicate a lack of past exploitation or discovery, rather than inherent invulnerability. The plugin has strengths in its limited attack surface and secure data handling for SQL and output, but the unsanitized paths present a weakness that requires careful review and potential remediation.

Key Concerns

  • Flows with unsanitized paths
  • External HTTP request without context
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

IranDargah Payment Gateway for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IranDargah Payment Gateway for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

87% escaped30 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle_response (includes\class-wc-gateway-irandargah.php:398)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

IranDargah Payment Gateway for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterwoocommerce_payment_gatewaysgateway-irandargah.php:36
actionplugins_loadedgateway-irandargah.php:38
actionwoocommerce_blocks_loadedgateway-irandargah.php:69
actionwoocommerce_blocks_payment_method_type_registrationgateway-irandargah.php:75
actionbefore_woocommerce_initgateway-irandargah.php:95
actionadmin_noticesgateway-irandargah.php:116
actionbefore_woocommerce_initincludes\class-wc-gateway-irandargah.php:17
filterwoocommerce_payment_gatewaysincludes\class-wc-gateway-irandargah.php:24
actionwoocommerce_api_wc_gateway_irandargahincludes\class-wc-gateway-irandargah.php:92
actionwoocommerce_receipt_irandargahincludes\class-wc-gateway-irandargah.php:94
actionadmin_noticesincludes\class-wc-gateway-irandargah.php:95
Maintenance & Trust

IranDargah Payment Gateway for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 8, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

IranDargah Payment Gateway for Woocommerce Developer Profile

irandargah

2 plugins · 510 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IranDargah Payment Gateway for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/irandargah-payment-gateway-for-woocommerce/assets/css/admin.css/wp-content/plugins/irandargah-payment-gateway-for-woocommerce/assets/js/admin.js/wp-content/plugins/irandargah-payment-gateway-for-woocommerce/assets/images/icon.svg
Script Paths
/wp-content/plugins/irandargah-payment-gateway-for-woocommerce/assets/js/admin.js
Version Parameters
irandargah-payment-gateway-for-woocommerce/assets/css/admin.css?ver=irandargah-payment-gateway-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
irandargah-payment-gateway-for-woocommerce
HTML Comments
<!-- IranDargah Payment Gateway --><!-- IranDargah --><!-- IranDargah Sandbox -->
Data Attributes
data-merchant-iddata-sandbox-mode
FAQ

Frequently Asked Questions about IranDargah Payment Gateway for Woocommerce