
KueskiPay Gateway Security & Risk Analysis
wordpress.org/plugins/kueskipay-gatewayAdd Kueski gateway to buy now and pay later on your store.
Is KueskiPay Gateway Safe to Use in 2026?
Generally Safe
Score 100/100KueskiPay Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kueskipay-gateway plugin version 2.4.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and having a very high rate of properly escaped output. It also has no known vulnerabilities (CVEs) recorded, suggesting a history of stable and secure development.
However, significant security concerns arise from the attack surface analysis. The plugin has two identified entry points: one AJAX handler and one REST API route. Crucially, both of these entry points lack proper authentication and permission checks, making them directly accessible to unauthenticated users. This is a critical security flaw that could lead to unauthorized actions or data exposure. While taint analysis shows no immediate risks, the presence of unprotected entry points is a substantial vulnerability regardless of specific taint flows being identified.
In conclusion, while the plugin's handling of SQL and output escaping is commendable, the absence of authentication checks on its AJAX and REST API endpoints represents a major security weakness. This oversight significantly increases the risk profile and should be addressed immediately. The lack of historical vulnerabilities is a positive indicator, but it does not mitigate the immediate risks posed by the exposed entry points.
Key Concerns
- AJAX handler without auth check
- REST API route without permission callback
KueskiPay Gateway Security Vulnerabilities
KueskiPay Gateway Code Analysis
Output Escaping
KueskiPay Gateway Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 22
Scheduled Events 1
Maintenance & Trust
KueskiPay Gateway Maintenance & Trust
Maintenance Signals
Community Trust
KueskiPay Gateway Alternatives
CityPay Paylink WooCommerce
citypay-payments
CityPay Paylink WooCommerce adds payment processing support to WooCommerce using CityPay hosted forms.
iCard Checkout for WooCommerce
icard-checkout-for-woocommerce
A one-click checkout with a full range of payment services and regular settlement of funds
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
Conversion Tracking for WooCommerce
woocommerce-conversion-tracking
Adds various conversion tracking codes to cart, checkout, registration success and product page on WooCommerce
Kustom Checkout for WooCommerce
klarna-checkout-for-woocommerce
The leading checkout in the Nordics, built for higher conversion and returning shoppers. Easy to integrate, supports Klarna and all popular payment me …
KueskiPay Gateway Developer Profile
1 plugin · 200 total installs
How We Detect KueskiPay Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kueskipay-gateway/assets/js/kueski-checkout-gateway.js/wp-content/plugins/kueskipay-gateway/assets/js/kueski-gateway.js/wp-content/plugins/kueskipay-gateway/assets/css/kueski-gateway.css/wp-content/plugins/kueskipay-gateway/assets/js/kueski-checkout-gateway.js/wp-content/plugins/kueskipay-gateway/assets/js/kueski-gateway.jskueskipay-gateway/assets/js/kueski-checkout-gateway.js?ver=kueskipay-gateway/assets/js/kueski-gateway.js?ver=kueskipay-gateway/assets/css/kueski-gateway.css?ver=HTML / DOM Fingerprints
kueski-list-table<!-- KUESKI GATEWAY: Payment form --><!-- KUESKI GATEWAY: Payment form end -->data-kueski-initkueski_payment_params/wp-json/kueski-gateway/v1/payment[kueski_pay_button]