Payment Gateway for Telcell Security & Risk Analysis

wordpress.org/plugins/payment-gateway-for-telcell

Payment Gateway for Telcell-ը միջազգային WooCommerce հարթակի պլագին է, որը հնարավորություն է ստեղծում Ձեր կայքը հեշտությամբ ինտեգրել Telcell վճարային …

100 active installs v2.0.4 PHP 5.6+ WP 4.8+ Updated Mar 1, 2024
payment-systemtelcell
85
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 27, 2024
Safety Verdict

Is Payment Gateway for Telcell Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for Telcell has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 27, 2024Updated 2yr ago
Risk Assessment

The 'payment-gateway-for-telcell' plugin v2.0.4 presents a mixed security posture. On the positive side, the static analysis reveals a clean codebase with no identified dangerous functions, file operations, or bundled libraries. The SQL queries are all properly prepared, and output escaping is robust at 98%, indicating good practices in these areas. The absence of a significant attack surface through AJAX, REST API, shortcodes, or cron events is also a strength. However, the presence of 5 external HTTP requests and the critical finding of 5 unsanitized paths in the taint analysis are significant concerns that warrant attention. While the plugin has had a known vulnerability in the past (URL Redirection), it is currently patched and not an immediate threat, but it highlights a historical area of weakness that could resurface if not carefully managed.

The lack of nonce checks and capability checks across all identified entry points (even though the static analysis reports zero entry points) is a notable absence of standard WordPress security measures. This, combined with the taint analysis indicating flows with unsanitized paths, suggests a potential risk of sensitive data being mishandled or processed improperly, especially concerning the external HTTP requests which might be influenced by these paths. The historical 'Open Redirect' vulnerability, though patched, serves as a reminder that the plugin has had issues with how external data is handled, which could be exacerbated by the identified unsanitized paths.

Key Concerns

  • Taint flows with unsanitized paths (5)
  • No nonce checks
  • No capability checks
  • External HTTP requests (5)
  • Past 'Open Redirect' vulnerability
Vulnerabilities
1

Payment Gateway for Telcell Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-6786medium · 6.1URL Redirection to Untrusted Site ('Open Redirect')

Payment Gateway for Telcell <= 2.0.3 - Open Redirect

Feb 27, 2024 Patched in 2.0.4 (456d)
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for Telcell Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
102 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

98% escaped104 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
hkdigital_init_telcell_gateway_class (includes\main.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payment Gateway for Telcell Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_initincludes\activate.php:3
filterplugin_localeincludes\language.php:4
actionplugins_loadedincludes\main.php:3
actionwoocommerce_api_telcell_redirectincludes\main.php:70
actionwoocommerce_api_telcell_resultincludes\main.php:75
filterwoocommerce_available_payment_gatewaysincludes\main.php:77
actionadmin_print_stylesincludes\main.php:79
filterwoocommerce_payment_gatewayswc-hkdigital-telcell-gateway.php:42
actionwoocommerce_blocks_loadedwc-hkdigital-telcell-gateway.php:67
actionwoocommerce_blocks_payment_method_type_registrationwc-hkdigital-telcell-gateway.php:75
actionbefore_woocommerce_initwc-hkdigital-telcell-gateway.php:99
Maintenance & Trust

Payment Gateway for Telcell Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 1, 2024
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Payment Gateway for Telcell Developer Profile

HK Digital Agency LLC

11 plugins · 660 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
456 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for Telcell

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-for-telcell/assets/images/logo_checkout_telcell.png

HTML / DOM Fingerprints

JS Globals
Telcell_Blocks_Support
REST Endpoints
/wp-json/payment-gateway-for-telcell/v1/telcell-gateway
FAQ

Frequently Asked Questions about Payment Gateway for Telcell