PayIQ WooCommerce Gateway Security & Risk Analysis

wordpress.org/plugins/payiq-wc-gateway

This plugins integrates you WooCommerce store with PayIQs payment service

10 active installs v1.2 PHP + WP 4.0+ Updated Unknown
gatewaypayiqpaymentswoocommercewoocommmerce-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayIQ WooCommerce Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

PayIQ WooCommerce Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'payiq-wc-gateway' v1.2 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identified CVEs, suggesting a history of responsible development or fewer targeted vulnerabilities. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's direct attack surface. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests or bundled libraries to consider. This indicates a strong adherence to secure coding practices in these critical areas.

However, there are significant concerns regarding output escaping and capability checks. A very low percentage (5%) of outputs are properly escaped, which presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not properly sanitized before being displayed can be exploited. Additionally, the complete lack of capability checks and nonce checks, especially given the presence of file operations, indicates a potential for unauthorized actions if any of the entry points were to be discovered or if file operations could be triggered in an unintended way. The absence of taint analysis results is also noted; while not necessarily a negative, it means there were no flows analyzed, so no certainty can be drawn from this aspect.

In conclusion, while the plugin benefits from a limited attack surface and secure SQL practices, the severely inadequate output escaping is a critical weakness that overshadows these strengths. The lack of capability and nonce checks further amplifies the risk associated with any unescaped output or file operations. Addressing the output escaping issue should be the highest priority to improve the plugin's security.

Key Concerns

  • Poor output escaping
  • Missing capability checks
  • Missing nonce checks
  • File operations without auth checks implied
Vulnerabilities
None known

PayIQ WooCommerce Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PayIQ WooCommerce Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
59
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped62 total outputs
Attack Surface

PayIQ WooCommerce Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitclasses\class-payiq.php:9
actionadmin_menuclasses\class-payiq.php:75
actionwoocommerce_order_status_completedclasses\class-payiq.php:79
actionwoocommerce_admin_order_data_after_order_detailsclasses\class-payiq.php:81
actionwoocommerce_scheduled_subscription_payment_payiqclasses\class-payiq.php:83
actionplugins_loadedgateway-payiq.php:20
actionadmin_noticesgateway-payiq.php:33
filterwoocommerce_payment_gatewaysgateway-payiq.php:72
Maintenance & Trust

PayIQ WooCommerce Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PayIQ WooCommerce Gateway Developer Profile

Peter Elmered

3 plugins · 320 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayIQ WooCommerce Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payiq-wc-gateway/assets/css/payiq-wc-gateway-backend.css/wp-content/plugins/payiq-wc-gateway/assets/js/payiq-wc-gateway-backend.js
Version Parameters
payiq-wc-gateway/assets/css/payiq-wc-gateway-backend.css?ver=payiq-wc-gateway/assets/js/payiq-wc-gateway-backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
payiq_fields
FAQ

Frequently Asked Questions about PayIQ WooCommerce Gateway