iswipe payment gateway Security & Risk Analysis

wordpress.org/plugins/iswipe-payment-gateway

iSwipe is a cryptocurrency payment gateway with an instant and automatic conversion of a wide range of cryptocurrencies into Euro/USD.

0 active installs v1.2.0 PHP 5.6+ WP 4.6+ Updated Jul 2, 2018
automatic-cryptocurrency-exchangebitcoinbitcoin-cashcrypto-paymentscryptocurrency-payment-gateway
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is iswipe payment gateway Safe to Use in 2026?

Generally Safe

Score 85/100

iswipe payment gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "iswipe-payment-gateway" v1.2.0 plugin exhibits a generally positive security posture based on the provided static analysis. The plugin demonstrates good practices by having no apparent direct entry points such as AJAX handlers, REST API routes, or shortcodes that are exposed without authentication. Furthermore, all SQL queries are reportedly using prepared statements, and there are no recorded historical vulnerabilities, which suggests a diligent approach to security by the developers. The absence of critical or high severity taint flows is also a strong positive indicator.

However, there are areas for improvement. The low percentage of properly escaped output (33%) is a significant concern, as it indicates potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the browser without sufficient sanitization. While the attack surface is reported as zero entry points, the presence of file operations without further detail warrants scrutiny. The lack of any reported nonce or capability checks, coupled with the minimal output escaping, suggests that even if an indirect vulnerability were to be discovered, its exploitability might be higher than anticipated.

In conclusion, the plugin has a solid foundation with no known CVEs and the absence of critical code-level security flaws. The most prominent weakness lies in output escaping, which needs immediate attention. The developers should prioritize addressing this to prevent potential XSS attacks. Further investigation into the file operations would also be prudent. Overall, while not demonstrably vulnerable in its current state based on this data, the plugin has room to improve its robustness.

Key Concerns

  • Low percentage of properly escaped output
  • Presence of file operations without further detail
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

iswipe payment gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

iswipe payment gateway Release Timeline

v1.2.0Current
v1.1.0
v1.0
Code Analysis
Analyzed Mar 17, 2026

iswipe payment gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

iswipe payment gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadediswipe-payment.php:33
actionwoocommerce_api_wc_iswipe_payment_gatewayiswipe-payment.php:68
filterload_textdomain_mofileiswipe-payment.php:233
filterwoocommerce_payment_gatewaysiswipe-payment.php:239
Maintenance & Trust

iswipe payment gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 2, 2018
PHP min version5.6
Downloads1K

Community Trust

Rating88/100
Number of ratings5
Active installs0
Developer Profile

iswipe payment gateway Developer Profile

nikotech

2 plugins · 20K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect iswipe payment gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iswipe-payment-gateway/iswipe-style.css/wp-content/plugins/iswipe-payment-gateway/iswipe-script.js
Script Paths
https://widget.iswipe.net/checkout/widget.js

HTML / DOM Fingerprints

CSS Classes
uswipe-badgebtn-buy
Data Attributes
id="uswipe-badge"id="btn-buy"id="modal"
JS Globals
UswipeWidget
REST Endpoints
/wc-api/wc_iswipe_payment_gateway/
Shortcode Output
<div id="modal"> <div class="uswipe-badge" id="uswipe-badge"> </div> </div> <a href="#" class="btn btn-md btn-primary btn-buy" id="btn-buy"> buy</a>
FAQ

Frequently Asked Questions about iswipe payment gateway