Nochex Payment Gateway for Woocommerce Security & Risk Analysis

wordpress.org/plugins/nochex-payment-gateway-for-woocommerce

Accept all major credit cards directly on your WooCommerce website using the Nochex payment gateway. WooCommerce Version Tested up to 10.1.

50 active installs v3.0.1 PHP + WP 6.7+ Updated Sep 10, 2025
credit-cardsextensionnochexnochex-payment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nochex Payment Gateway for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Nochex Payment Gateway for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

Based on the static analysis, this plugin exhibits a strong security posture. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unescaped output is highly commendable. Furthermore, the plugin demonstrates excellent adherence to WordPress security best practices by implementing proper output escaping for all identified outputs and exclusively using prepared statements for any database interactions. The lack of an attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is also a significant strength, as it limits potential entry points for attackers.

However, there are a couple of areas that warrant attention. The plugin makes two external HTTP requests, and without more context on their purpose and the handling of their responses, there is a potential, albeit small, risk of issues like SSRF if not implemented securely. More importantly, the complete absence of nonce checks and capability checks across all entry points (though there are none identified) is a concerning pattern. While the current lack of an attack surface mitigates immediate risk, if the plugin were to evolve and introduce new entry points without these fundamental security measures, it would become highly vulnerable to CSRF attacks and unauthorized actions. The vulnerability history being completely clear is a positive indicator of past security efforts, but it doesn't negate the importance of proactive security implementation.

In conclusion, the "nochex-payment-gateway-for-woocommerce" plugin v3.0.1 demonstrates a strong foundation in secure coding practices, particularly regarding SQL and output sanitization. The lack of vulnerabilities and CVEs further reinforces this. However, the reliance on external HTTP requests and, most critically, the absence of any nonce or capability checks, represent potential weaknesses that should be addressed to ensure robust security, especially if the plugin's functionality expands in the future.

Key Concerns

  • No nonce checks
  • No capability checks
  • External HTTP requests without context
Vulnerabilities
None known

Nochex Payment Gateway for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Nochex Payment Gateway for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
101 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped101 total outputs
Attack Surface

Nochex Payment Gateway for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_noticesclass-nochex-payment-gateway-for-woocommerce.php:20
actionadmin_initclass-nochex-payment-gateway-for-woocommerce.php:21
actionplugins_loadedclass-nochex-payment-gateway-for-woocommerce.php:23
actionplugins_loadedclass-nochex-payment-gateway-for-woocommerce.php:48
actionwoocommerce_api_nochex_payment_gateway_for_woocommerceclass-nochex-payment-gateway-for-woocommerce.php:82
actionwoocommerce_receipt_nochexclass-nochex-payment-gateway-for-woocommerce.php:84
filterwoocommerce_available_payment_gatewaysclass-nochex-payment-gateway-for-woocommerce.php:86
filterwoocommerce_payment_gatewaysclass-nochex-payment-gateway-for-woocommerce.php:251
actionbefore_woocommerce_initclass-nochex-payment-gateway-for-woocommerce.php:265
actionwoocommerce_blocks_loadedclass-nochex-payment-gateway-for-woocommerce.php:268
actionwoocommerce_blocks_payment_method_type_registrationclass-nochex-payment-gateway-for-woocommerce.php:284
Maintenance & Trust

Nochex Payment Gateway for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 10, 2025
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Nochex Payment Gateway for Woocommerce Developer Profile

nochexdevteam

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nochex Payment Gateway for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nochex-payment-gateway-for-woocommerce/images/nochex-logo.png/wp-content/plugins/nochex-payment-gateway-for-woocommerce/includes/settings-nochex.php/wp-content/plugins/nochex-payment-gateway-for-woocommerce/includes/class-nochex-payment-gateway-for-woocommerce-request.php/wp-content/plugins/nochex-payment-gateway-for-woocommerce/includes/class-nochex-payment-gateway-for-woocommerce-apccallback.php

HTML / DOM Fingerprints

CSS Classes
inlineerror
HTML Comments
<!-- Nochex Validation - Check module enabled and if merchant field is blank / empty --><!-- Reload Nochex Settings for the merchant --><!-- Generate the HTML For the settings form. -->
Data Attributes
woocommerce_nochex_merchant_id
REST Endpoints
/wp-json/wc/v3/settings/payment_gateways
FAQ

Frequently Asked Questions about Nochex Payment Gateway for Woocommerce