Pacific Payment Gateway Security & Risk Analysis

wordpress.org/plugins/pacific-payment-gateway

Pacific payment gateway plugin for Woocommerce.

0 active installs v1.0.23 PHP 7.1+ WP 5.3+ Updated Sep 30, 2022
blikcardpacificpaymentpayment-gateway
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pacific Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Pacific Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "pacific-payment-gateway" plugin version 1.0.23 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-sized attack surface with no unprotected entry points. This significantly minimizes the potential for external exploitation. The code also shows good practices regarding dangerous functions and SQL queries, with all SQL queries utilizing prepared statements. File operations are present but isolated, and there are no external HTTP requests. However, a significant concern is the absence of nonce checks and capability checks, which are crucial for securing the plugin's functionality, especially if any hidden or future entry points are discovered. While the output escaping rate is relatively high at 81%, the 19% of unescaped output presents a potential risk for cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. This lack of historical vulnerabilities, combined with the current lack of critical taint flows, suggests a potentially well-developed and secure codebase. Overall, the plugin demonstrates strengths in minimizing its attack surface and using secure database practices. The primary weaknesses lie in the missing authentication and authorization checks (nonces and capabilities) and the presence of some unescaped output.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output detected
Vulnerabilities
None known

Pacific Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pacific Payment Gateway Release Timeline

v1.0.23Current
v1.0.21
v1.0.20
v1.0.19
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
Code Analysis
Analyzed Apr 6, 2026

Pacific Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped59 total outputs
Attack Surface

Pacific Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwoocommerce_initpacific-gateway.php:16
actionrest_api_initsrc/bootstrap.php:62
Maintenance & Trust

Pacific Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 30, 2022
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pacific Payment Gateway Developer Profile

pacificorg

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pacific Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pacific-payment-gateway/assets/css/pacific-gateway.css/wp-content/plugins/pacific-payment-gateway/assets/js/pacific-gateway.js/wp-content/plugins/pacific-payment-gateway/assets/js/payu-gateway.js/wp-content/plugins/pacific-payment-gateway/assets/css/inpost-gateway.css/wp-content/plugins/pacific-payment-gateway/assets/js/inpost-gateway.js
Script Paths
/wp-content/plugins/pacific-payment-gateway/assets/js/pacific-gateway.js/wp-content/plugins/pacific-payment-gateway/assets/js/payu-gateway.js/wp-content/plugins/pacific-payment-gateway/assets/js/inpost-gateway.js
Version Parameters
pacific-payment-gateway/assets/css/pacific-gateway.css?ver=pacific-payment-gateway/assets/js/pacific-gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
pacific_payment_gateway_boxpacific-payment-gateway-modal
Data Attributes
data-pacific-gateway-public-keydata-pacific-gateway-locale
JS Globals
pacificGatewaypacific_gateway_public_keypacific_gateway_locale
REST Endpoints
/wp-json/pacific-gateway/v1/payment/wp-json/pacific-gateway/v1/callback
Shortcode Output
[pacific_payment_gateway]
FAQ

Frequently Asked Questions about Pacific Payment Gateway