LatPay Direct Payment Gateway Security & Risk Analysis

wordpress.org/plugins/latpay-direct-payment

The LatPay Direct Payment Gateway plugin for Woocommerce allows you to accept the payments directly from your Wordpress website, seamlessly integratin …

10 active installs v1.0.5 PHP + WP 4.0+ Updated May 28, 2025
credit-cardse-commerceecommercepaymentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LatPay Direct Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

LatPay Direct Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "latpay-direct-payment" plugin version 1.0.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified CVEs and the complete lack of critical or high-severity taint flows are positive indicators. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, also contributes to a reduced risk profile.

However, there are notable areas of concern. The complete absence of nonce checks and capability checks across all entry points is a significant weakness. This means that even if the attack surface were larger, there would be no built-in protection against CSRF attacks or unauthorized access based on user roles. The presence of file operations and external HTTP requests, while not inherently dangerous, warrants further scrutiny as these can be vectors for vulnerabilities if not handled with extreme care and proper sanitization, especially given the lack of explicit authentication checks on any entry points. The lack of taint analysis results is also unusual; while it might mean no flows were found, it could also indicate limitations in the analysis tool's ability to identify complex flows in this specific plugin's code.

In conclusion, while the plugin's current version appears free of known vulnerabilities and follows good SQL and output handling practices, the complete lack of authentication and authorization checks on its entry points represents a substantial security risk. This, coupled with the potential for misuse of file operations and external requests without proper checks, requires careful consideration. The absence of any historical vulnerabilities is a positive sign of development diligence, but it does not negate the immediate risks identified in the static analysis.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • File operations without explicit auth checks
  • External HTTP requests without explicit auth checks
  • Low percentage of properly escaped output (76%)
Vulnerabilities
None known

LatPay Direct Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LatPay Direct Payment Gateway Release Timeline

v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

LatPay Direct Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

76% escaped21 total outputs
Attack Surface

LatPay Direct Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedhps-checkout-gateway.php:25
actionbefore_woocommerce_inithps-checkout-gateway.php:26
actionwp_loadedhps-checkout-gateway.php:62
actionwoocommerce_update_options_payment_gatewayshps-checkout-gateway.php:67
filterwoocommerce_payment_gatewayshps-checkout-gateway.php:642
Maintenance & Trust

LatPay Direct Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 28, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LatPay Direct Payment Gateway Developer Profile

LPS Technical Team

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LatPay Direct Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/latpay-direct-payment/images/cards.png
Script Paths
https://lateralpayments.com/checkout/Scripts/Latpay2.js
Version Parameters
latpay-direct-payment/style.css?ver=latpay-direct-payment/js/latpay_validation.js?ver=latpay-direct-payment/js/latpay_checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
latpay-cardcvc-fieldsetlatpay-card-groupwc-latpay-elements-fieldlatpay-containerlatpay-pay-data
Data Attributes
data-merchantiddata-publickeydata-currencydata-amount
JS Globals
LatpayCheckout
FAQ

Frequently Asked Questions about LatPay Direct Payment Gateway