Payment Gateway for ARMECONOMBANK Security & Risk Analysis

wordpress.org/plugins/payment-gateway-for-armeconombank

Payment Gateway for ARMECONOMBANK – միջազգային Woocomerce հավելվածի հավելում է, որը ստեղծում է հնարավորություն` հեշտությամբ ինտեգրել կայքին ՀԱՅԷԿՈՆՈՄԲ …

10 active installs v1.0.5 PHP 5.6+ WP 5.1+ Updated Jan 12, 2024
armeconombankpayment-system
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for ARMECONOMBANK Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for ARMECONOMBANK has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "payment-gateway-for-armeconombank" plugin v1.0.5 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and its SQL queries are all properly prepared. The absence of file operations and dangerous functions is also a good sign. However, there are significant concerns related to the code analysis. The plugin has a high percentage of unescaped output (48%), indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. Additionally, the presence of 6 taint flows with unsanitized paths, even if not classified as critical or high severity in the static analysis, suggests potential for information leakage or unexpected behavior if these paths are triggered by malicious input.

Furthermore, the plugin lacks any apparent nonce checks or capability checks for its entry points, and it has a single cron event which might not have proper authorization. While there are no currently unpatched CVEs, this doesn't negate the risks identified in the static analysis. The plugin's strengths lie in its safe handling of SQL and lack of external vulnerabilities. The weaknesses are primarily within the code itself, pointing to potential vulnerabilities that require further investigation and remediation. The current findings suggest a moderate risk level, with a need for immediate attention to output escaping and taint flow analysis.

Key Concerns

  • Significant unescaped output detected
  • Multiple taint flows with unsanitized paths
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Payment Gateway for ARMECONOMBANK Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Payment Gateway for ARMECONOMBANK Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Payment Gateway for ARMECONOMBANK Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
25
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
21
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

52% escaped52 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
hkd_init_armeconombank_gateway_class (includes/main.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payment Gateway for ARMECONOMBANK Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
filtercron_schedulesconsole/command.php:20
actioninitconsole/command.php:30
actionadmin_initincludes/activate.php:3
filterplugin_localeincludes/language.php:4
actionplugins_loadedincludes/main.php:3
actionwoocommerce_scheduled_subscription_paymentincludes/main.php:153
actionwoocommerce_api_delete_binding_armeconombankincludes/main.php:159
actionwoocommerce_api_armeconombank_successfulincludes/main.php:166
actionwoocommerce_api_armeconombank_failedincludes/main.php:171
actionadmin_print_stylesincludes/main.php:176
filterquery_varsincludes/main.php:183
filterwoocommerce_account_menu_itemsincludes/main.php:184
actionwoocommerce_account_cards_endpointincludes/main.php:185
filterwoocommerce_admin_order_actionsincludes/main.php:193
actionadmin_headincludes/main.php:194
actionwoocommerce_order_status_changedincludes/main.php:195
actionwoocommerce_order_edit_statusincludes/main.php:196
actioncronCheckOrderArmeconombankincludes/main.php:201
actionwoocommerce_thankyouincludes/thankyou.php:3
filterwoocommerce_payment_gatewayswc-hkdigital-armeconombank-gateway.php:39

Scheduled Events 1

cronCheckOrderArmeconombank
Maintenance & Trust

Payment Gateway for ARMECONOMBANK Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 12, 2024
PHP min version5.6
Downloads980

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Payment Gateway for ARMECONOMBANK Developer Profile

HK Digital Agency LLC

13 plugins · 690 total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
275 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for ARMECONOMBANK

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-for-armeconombank/assets/images/cards.png

HTML / DOM Fingerprints

CSS Classes
hkd_armeconombank
Data Attributes
data-checkout-iddata-gateway-id
JS Globals
hkd_armeconombank_obj
FAQ

Frequently Asked Questions about Payment Gateway for ARMECONOMBANK