Payment Gateway for IDBANK Security & Risk Analysis

wordpress.org/plugins/payment-gateway-for-idbank

Secure payment gateway integration for IDBANK - Accept online payments through IDBANK's payment system with full WooCommerce compatibility.

10 active installs v1.0.8 PHP 7.4+ WP 5.0+ Updated Nov 9, 2025
armeniaidbankonline-paymentspayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for IDBANK Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway for IDBANK has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "payment-gateway-for-idbank" plugin version 1.0.8 presents a mixed security posture. On the positive side, the plugin has a seemingly small attack surface with no detected AJAX handlers, REST API routes, or shortcodes that are immediately exposed. Furthermore, there are no known historical vulnerabilities (CVEs) associated with this plugin, which suggests a generally stable development history. The absence of dangerous functions and file operations also contributes to a good baseline security practice.

However, several areas raise concerns. The most significant is the handling of SQL queries, where 100% of them are not using prepared statements. This is a critical security risk that could lead to SQL injection vulnerabilities. The taint analysis reveals 4 flows with unsanitized paths, though thankfully no critical or high severity issues were flagged directly by the taint analysis in this iteration. While the output escaping is generally good at 72%, the remaining 28% that are not properly escaped could still lead to cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin benefits from a lack of known vulnerabilities and a controlled attack surface, the unescaped SQL queries represent a severe and actionable risk. The presence of unsanitized paths in taint flows, even without immediate critical severity, warrants attention. Developers should prioritize addressing the SQL query sanitation and investigate the identified unsanitized paths to ensure robust security.

Key Concerns

  • 100% of SQL queries not using prepared statements
  • 4 flows with unsanitized paths in taint analysis
  • 28% of outputs not properly escaped
  • No capability checks found
Vulnerabilities
None known

Payment Gateway for IDBANK Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for IDBANK Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
21
53 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

72% escaped74 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

6 flows4 with unsanitized paths
webhook_idbank_successful (includes\main.php:1323)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payment Gateway for IDBANK Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
filtercron_schedulesconsole\command.php:24
actioninitconsole\command.php:36
actionadmin_initincludes\activate.php:4
filterplugin_localeincludes\language.php:4
actionplugins_loadedincludes\main.php:5
actionwoocommerce_scheduled_subscription_paymentincludes\main.php:161
actionwoocommerce_api_delete_binding_idbankincludes\main.php:167
actionwoocommerce_api_idbank_successfulincludes\main.php:174
actionwoocommerce_api_idbank_failedincludes\main.php:179
actionadmin_print_stylesincludes\main.php:183
filterquery_varsincludes\main.php:190
filterwoocommerce_account_menu_itemsincludes\main.php:191
actionwoocommerce_account_cards_endpointincludes\main.php:192
filterwoocommerce_admin_order_actionsincludes\main.php:200
actionadmin_headincludes\main.php:201
actionwoocommerce_order_status_changedincludes\main.php:204
actionwoocommerce_order_edit_statusincludes\main.php:205
actioncronCheckOrderIDBankincludes\main.php:210
actionwoocommerce_thankyouincludes\thankyou.php:5
actioninitwc-payment-gateway-for-idbank.php:24
filterwoocommerce_payment_gatewayswc-payment-gateway-for-idbank.php:41
actionwoocommerce_blocks_loadedwc-payment-gateway-for-idbank.php:67
actionwoocommerce_blocks_payment_method_type_registrationwc-payment-gateway-for-idbank.php:74
actionbefore_woocommerce_initwc-payment-gateway-for-idbank.php:97
actionadmin_footerwc-payment-gateway-for-idbank.php:114

Scheduled Events 1

cronCheckOrderIDBank
Maintenance & Trust

Payment Gateway for IDBANK Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 9, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Payment Gateway for IDBANK Developer Profile

HK Digital Agency LLC

11 plugins · 660 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
456 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for IDBANK

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-for-idbank/css/style.css/wp-content/plugins/payment-gateway-for-idbank/js/idbank-payment-gateway.js/wp-content/plugins/payment-gateway-for-idbank/includes/js/idbank-frontend.js/wp-content/plugins/payment-gateway-for-idbank/includes/js/idbank-validation.js/wp-content/plugins/payment-gateway-for-idbank/includes/js/idbank-checkout.js
Version Parameters
/wp-content/plugins/payment-gateway-for-idbank/css/style.css?ver=/wp-content/plugins/payment-gateway-for-idbank/js/idbank-payment-gateway.js?ver=/wp-content/plugins/payment-gateway-for-idbank/includes/js/idbank-frontend.js?ver=/wp-content/plugins/payment-gateway-for-idbank/includes/js/idbank-validation.js?ver=/wp-content/plugins/payment-gateway-for-idbank/includes/js/idbank-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
hkd_idbank_gateway_setting_link
JS Globals
window.hkdIdbankMoveAllNotices
FAQ

Frequently Asked Questions about Payment Gateway for IDBANK