
Jigoshop Custom Payment Gateway Security & Risk Analysis
wordpress.org/plugins/jigoshop-custom-payment-gatewayThis plugin adds a simple custom payment gateway similar to the "Cheque" gateway that can be molded for your projects.
Is Jigoshop Custom Payment Gateway Safe to Use in 2026?
Generally Safe
Score 85/100Jigoshop Custom Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "jigoshop-custom-payment-gateway" v1.0.1 exhibits a concerning security posture primarily due to significant output escaping deficiencies. While the plugin boasts an attack surface with zero entry points and no known historical vulnerabilities, the static analysis reveals a critical weakness: 100% of its output is not properly escaped. This means that any data processed or displayed by the plugin could potentially be exploited to inject malicious code, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, taint analysis indicated three flows with unsanitized paths, which, although not classified as critical or high severity, still represent potential risks that could be exacerbated by the lack of output escaping.
The absence of known CVEs and historical vulnerabilities is a positive sign, suggesting a potentially clean development history or a lack of widespread exploitation. However, this should not be interpreted as a guarantee of absolute security, especially given the identified output escaping issues. The plugin's strengths lie in its clean attack surface and the absence of dangerous functions or unescaped SQL queries. Nevertheless, the lack of output escaping represents a fundamental security flaw that makes the plugin highly vulnerable to XSS attacks, outweighing the positive aspects of its current known history and attack surface.
Key Concerns
- All output is unescaped
- Flows with unsanitized paths detected
Jigoshop Custom Payment Gateway Security Vulnerabilities
Jigoshop Custom Payment Gateway Code Analysis
Output Escaping
Data Flow Analysis
Jigoshop Custom Payment Gateway Attack Surface
WordPress Hooks 4
Maintenance & Trust
Jigoshop Custom Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Jigoshop Custom Payment Gateway Alternatives
Jigoshop Credimax
jigoshop-credimax
This plugin extends the Jigoshop payment gateways to add in Credimax Payment Gateway.
Easy Digital Downloads – Empty Cart
easy-digital-downloads-empty-cart
Easily add content to the empty cart display in Easy Digital Downloads.
Easy Digital Downloads – Continue Shopping
easy-digital-downloads-continue-shopping
Adds a Continue Shopping link to the Easy Digital Downloads checkout cart.
Auto Register for WooCommerce
auto-register-for-woocommerce
Once activated, Auto Register for WooCommerce will create a WordPress user account for your customer
Easy Digital Downloads – Clear Cart
easy-digital-downloads-clear-cart
Adds a Clear Cart link to the Easy Digital Downloads checkout cart.
Jigoshop Custom Payment Gateway Developer Profile
5 plugins · 610 total installs
How We Detect Jigoshop Custom Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
id="jigoshop_tgm_custom_gateway_enabled"name="jigoshop_tgm_custom_gateway_enabled"id="jigoshop_tgm_custom_gateway_title"name="jigoshop_tgm_custom_gateway_title"id="jigoshop_tgm_custom_gateway_description"name="jigoshop_tgm_custom_gateway_description"jigoshop_tgm_custom_gatewayClient PaymentsThis payment gateway is setup specifically for client billing accounts. Orders will be processed and billed directly to existing client accounts.