درگاه پرداخت بانک ملت ووکامرس Security & Risk Analysis

wordpress.org/plugins/mellat-woocommerce

پرداخت اینترنتی وجه به وسیله درگاه پرداخت بانک ملت

3K active installs v4.2.0 PHP + WP 4.0+ Updated Dec 9, 2021
commercee-commerceshopwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is درگاه پرداخت بانک ملت ووکامرس Safe to Use in 2026?

Generally Safe

Score 85/100

درگاه پرداخت بانک ملت ووکامرس has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of the "mellat-woocommerce" v4.2.0 plugin reveals a generally positive security posture. There are no identified critical vulnerabilities in the code signals or taint analysis, and the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further contribute to a strong security foundation.

However, some areas warrant attention. The complete lack of nonce checks and capability checks across all entry points is a significant concern. While the current attack surface is reported as zero, any future introduction of AJAX handlers, REST API routes, or shortcodes without these essential security mechanisms could expose the plugin to cross-site request forgery (CSRF) and unauthorized action vulnerabilities. The presence of file operations and an external HTTP request, without further context on their implementation, could also represent potential risks if not handled with extreme care.

In conclusion, the "mellat-woocommerce" plugin v4.2.0 appears to be well-written with respect to its handling of data and code execution, especially regarding SQL and output sanitization. Its vulnerability history is reassuring. The primary weakness lies in the fundamental absence of authorization checks (nonces and capabilities) on all potential entry points, which, if not addressed, presents a latent risk for future development or unforeseen attack vectors.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

درگاه پرداخت بانک ملت ووکامرس Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

درگاه پرداخت بانک ملت ووکامرس Release Timeline

v4.2.0Current
v4.1.0
v4.0.3
v4.0.2
v4.0.1
v4.0.0
Code Analysis
Analyzed Mar 16, 2026

درگاه پرداخت بانک ملت ووکامرس Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
1
Bundled Libraries
0

Output Escaping

89% escaped37 total outputs
Attack Surface

درگاه پرداخت بانک ملت ووکامرس Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initclass-wc-gateway-bankmellat.php:4
actionadmin_noticesclass-wc-gateway-bankmellat.php:5
filterwoocommerce_payment_gatewaysclass-wc-gateway-bankmellat.php:8
actionwoocommerce_update_options_payment_gatewaysclass-wc-gateway-bankmellat.php:87
actionplugins_loadedclass-wc-gateway-bankmellat.php:941
Maintenance & Trust

درگاه پرداخت بانک ملت ووکامرس Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 9, 2021
PHP min version
Downloads137K

Community Trust

Rating76/100
Number of ratings12
Active installs3K
Developer Profile

درگاه پرداخت بانک ملت ووکامرس Developer Profile

PersianScript

3 plugins · 143K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
528 days
View full developer profile
Detection Fingerprints

How We Detect درگاه پرداخت بانک ملت ووکامرس

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mellat-woocommerce/assets/images/logo.png

HTML / DOM Fingerprints

CSS Classes
notice-success
Data Attributes
data-action
REST Endpoints
woocommerce_api_wc_gateway_bankmellat
Shortcode Output
<h3>نسخه حرفه ای درگاه پرداخت ملت ووکامرس منتشر شد</h3><p>تفاوت نسخه رایگان با حرفه ای چیست؟</p><ul><li>پشتیبانی حرفه ای از طریق تیکت و تلفن</li>
FAQ

Frequently Asked Questions about درگاه پرداخت بانک ملت ووکامرس