
Ni WooCommerce Payment Gateway Charges Security & Risk Analysis
wordpress.org/plugins/ni-woocommerce-payment-gateway-chargesThe Ni WooCommerce Payment Gateway Charges plugin offers the capability to apply additional payment amounts or fees based on the customer's selec …
Is Ni WooCommerce Payment Gateway Charges Safe to Use in 2026?
Generally Safe
Score 85/100Ni WooCommerce Payment Gateway Charges has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ni-woocommerce-payment-gateway-charges plugin v1.6.0 demonstrates a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs, suggesting a level of diligence in past development and maintenance. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors.
However, several significant concerns are highlighted by the static analysis. The plugin has a complete lack of nonce checks and capability checks across all its entry points, which are critical for preventing Cross-Site Request Forgery (CSRF) and unauthorized actions. Furthermore, a striking 86% of output is not properly escaped, creating a high risk for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing two flows with unsanitized paths, though not classified as critical or high severity in this report, warrants attention given the unescaped output and missing authorization checks.
In conclusion, while the plugin benefits from secure SQL handling and a clean vulnerability history, the prevalent lack of input validation (nonces) and authorization (capabilities), coupled with widespread unescaped output, presents substantial security risks. These weaknesses, particularly the XSS potential and CSRF vulnerability, outweigh the strengths and require immediate remediation.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- High percentage of unescaped output
- Unsanitized paths in taint analysis flows
Ni WooCommerce Payment Gateway Charges Security Vulnerabilities
Ni WooCommerce Payment Gateway Charges Release Timeline
Ni WooCommerce Payment Gateway Charges Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ni WooCommerce Payment Gateway Charges Attack Surface
WordPress Hooks 9
Maintenance & Trust
Ni WooCommerce Payment Gateway Charges Maintenance & Trust
Maintenance Signals
Community Trust
Ni WooCommerce Payment Gateway Charges Alternatives
PayPlus Payment Gateway
payplus-payment-gateway
Accept credit/debit card payments or other methods such as bit, Apple Pay, Google Pay in one page. Create digitally signed invoices & much more!
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
Ni WooCommerce Payment Gateway Charges Developer Profile
26 plugins · 5K total installs
How We Detect Ni WooCommerce Payment Gateway Charges
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/css/niwoopgc.css/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/css/font-awesome.css/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/amcharts/amcharts.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/amcharts/light.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/amcharts/pie.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/css/lib/bootstrap.min.css/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/lib/bootstrap.min.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/lib/popper.min.js+1 more/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/amcharts/amcharts.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/amcharts/light.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/amcharts/pie.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/lib/bootstrap.min.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/admin/js/lib/popper.min.js/wp-content/plugins/ni-woocommerce-payment-gateway-charges/js/ni-payment-gateway-charges-script.jsHTML / DOM Fingerprints
niwoopgc-styleniwoopgc-font-awesome-cssniwoopgc-bootstrap-cssComment on 03-Jan-2018End Comment on 03-Jan-2018niwoopgc-styleniwoopgc-font-awesome-cssniwoopgc-amcharts-scriptniwoopgc-light-scriptniwoopgc-pie-scriptniwoopgc-bootstrap-css+3 more