iyzico for WooCommerce Security & Risk Analysis

wordpress.org/plugins/iyzico-woocommerce

iyzico latest payment processing solution. Accept credit/debit cards, alternative digital wallets and bank accounts.

10K active installs v3.5.28 PHP 7.4.33+ WP 6.6.2+ Updated Dec 23, 2025
checkout-woocommercecredit-cardecommerceiyzicopayment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is iyzico for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

iyzico for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "iyzico-woocommerce" plugin v3.5.28 demonstrates a generally good security posture, with no known vulnerabilities (CVEs) and a strong emphasis on secure coding practices. The static analysis reveals a limited attack surface, with no unprotected AJAX handlers or REST API routes. Furthermore, the code signals indicate a high percentage of properly escaped output and a significant portion of SQL queries utilizing prepared statements, which are positive indicators of security awareness. The absence of critical or high severity taint analysis findings further reinforces this positive assessment.

However, there are areas for improvement. The presence of 19 SQL queries with only 53% using prepared statements suggests a potential for SQL injection vulnerabilities in the remaining queries. Additionally, the plugin has 2 cron events which could be an entry point if not properly secured. While the vulnerability history is clean, indicating diligent maintenance, the lack of capability checks on any entry points is a concern. Without capability checks, any authenticated user, regardless of their role or permissions, could potentially trigger these functions, leading to unauthorized actions or information disclosure. Overall, the plugin is well-maintained and appears to be built with security in mind, but these specific areas warrant further investigation and hardening.

Key Concerns

  • SQL queries not using prepared statements
  • No capability checks on entry points
Vulnerabilities
None known

iyzico for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

iyzico for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
10 prepared
Unescaped Output
9
59 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

53% prepared19 total queries

Output Escaping

87% escaped68 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
getIyziOrder (includes\Common\Helpers\PaymentProcessor.php:97)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

iyzico for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_iyzico_iframe_loadedincludes\Common\Hooks\PublicHooks.php:48
noprivwp_ajax_iyzico_iframe_loadedincludes\Common\Hooks\PublicHooks.php:49
WordPress Hooks 16
actionwoocommerce_blocks_loadedincludes\Common\Helpers\BlocksSupport.php:23
actionbefore_woocommerce_initincludes\Common\Helpers\BlocksSupport.php:24
actionwoocommerce_blocks_payment_method_type_registrationincludes\Common\Helpers\BlocksSupport.php:36
actionbefore_woocommerce_initincludes\Common\Helpers\HighPerformanceOrderStorageSupport.php:11
actioniyzico_generate_google_products_xmlincludes\Common\Helpers\PluginUpdateHandler.php:47
actioniyzico_generate_google_products_xml_activationincludes\Common\Helpers\PluginUpdateHandler.php:59
actionrest_api_initincludes\Common\Hooks\PublicHooks.php:17
actionwoocommerce_receipt_iyzicoincludes\Common\Hooks\PublicHooks.php:21
actionwoocommerce_api_requestincludes\Common\Hooks\PublicHooks.php:26
actionwoocommerce_before_checkout_formincludes\Common\Hooks\PublicHooks.php:30
actionwp_footerincludes\Common\Hooks\PublicHooks.php:34
actionwp_enqueue_scriptsincludes\Common\Hooks\PublicHooks.php:39
actionwoocommerce_after_add_to_cart_formincludes\Common\Hooks\PublicHooks.php:44
actionrest_api_initincludes\Common\Hooks\RestHooks.php:18
actionupgrader_process_completewoocommerce-gateway-iyzico.php:67
actionplugins_loadedwoocommerce-gateway-iyzico.php:72

Scheduled Events 2

iyzico_generate_google_products_xml
iyzico_generate_google_products_xml
Maintenance & Trust

iyzico for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 23, 2025
PHP min version7.4.33
Downloads203K

Community Trust

Rating34/100
Number of ratings19
Active installs10K
Developer Profile

iyzico for WooCommerce Developer Profile

iyzico

1 plugin · 10K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect iyzico for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iyzico-woocommerce/assets/css/iyzico-checkout-styles.css/wp-content/plugins/iyzico-woocommerce/assets/js/iyzico-checkout-scripts.js
Script Paths
/wp-content/plugins/iyzico-woocommerce/assets/js/iyzico-checkout-scripts.js
Version Parameters
iyzico-woocommerce/assets/css/iyzico-checkout-styles.css?ver=iyzico-woocommerce/assets/js/iyzico-checkout-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
iyzico-checkout-formiyzico-checkout-button
HTML Comments
<!-- iyzico Checkout Payment Gateway -->
Data Attributes
data-iyzico-api-keydata-iyzico-secret-keydata-iyzico-base-urldata-iyzico-form-languagedata-iyzico-overlay-script
JS Globals
iyzicoCheckoutConfig
REST Endpoints
/wp-json/iyzico-woocommerce/v1/payment-status
Shortcode Output
[iyzico_checkout_form]
FAQ

Frequently Asked Questions about iyzico for WooCommerce