
NLB Payment Gateway For Woocommerce Security & Risk Analysis
wordpress.org/plugins/nlb-payment-gateway-for-woocommerceImplements the Tebank payment gateway.
Is NLB Payment Gateway For Woocommerce Safe to Use in 2026?
Generally Safe
Score 85/100NLB Payment Gateway For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nlb-payment-gateway-for-woocommerce" plugin version 2.0.1 exhibits a concerning security posture due to a significant number of unprotected entry points into the application. All four identified REST API routes lack permission callbacks, meaning any user, regardless of their role or authentication status, could potentially interact with these endpoints. This creates a wide attack surface. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and appears to have no recorded vulnerabilities or critical taint flows, the lack of authorization checks on its REST API endpoints is a major oversight. The static analysis also indicates that 50% of its output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. The absence of nonce checks further exacerbates the risk of CSRF attacks. The plugin's clean vulnerability history is a positive sign, suggesting a generally well-maintained codebase, but this should not overshadow the critical security gaps identified in the current version's entry point handling and output sanitization.
Key Concerns
- REST API routes without permission callbacks
- Output escaping issues
- Missing nonce checks
NLB Payment Gateway For Woocommerce Security Vulnerabilities
NLB Payment Gateway For Woocommerce Code Analysis
Output Escaping
NLB Payment Gateway For Woocommerce Attack Surface
REST API Routes 4
WordPress Hooks 14
Maintenance & Trust
NLB Payment Gateway For Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
NLB Payment Gateway For Woocommerce Alternatives
Advance Bank Payment Transfer Gateway
advance-bank-payment-transfer-gateway
Short Description: This plugin clones the Direct Bank Transfer gateway to create another offline payment method. License: GPLv2 or later
Payment Gateway for Paybox on Woocommerce
wc-paybox-payment-gateway
Payment Gateway for Paybox by Israel Discount Bank.
Halk Bank Payment Gateway For Woocommerce – not functional after 15.03.2024
woo-halkbank-payment-gateway
Implements the Halk bank payment gateway.
QR Payments Gateway
qr-pay-gateway
QR Payments For Woocommerce Payment Gateway for the following e-wallets
Bangladeshi Bank Payment Method
bangladeshi-bank-payment-method
WooCommerce gateway for Bangladeshi businesses allowing customers to upload bank payment receipts at checkout.
NLB Payment Gateway For Woocommerce Developer Profile
2 plugins · 140 total installs
How We Detect NLB Payment Gateway For Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nlb-payment-gateway-for-woocommerce/bankar-files/initClientAutoload.php/wp-content/plugins/nlb-payment-gateway-for-woocommerce/classes/class-woocomemrce-nlb-payment-bankart.phpnlb-payment-gateway-for-woocommerce/style.css?ver=nlb-payment-gateway-for-woocommerce/script.js?ver=HTML / DOM Fingerprints
WC_Gateway_tebank/tebank_payment_gateway/v1/order/(?P<id>\d+)