Payment Gateway for WooCommerce – Helcim Security & Risk Analysis

wordpress.org/plugins/payment-gateway-for-woocommerce-by-helcim

The Woocommerce Payment Gateway developed by Helcim Inc.

10 active installs v1.0.7 PHP + WP + Updated Apr 27, 2017
payment-gatewaypayment-gateway-for-woocommercewoocommercewoocommerce-payment-gatewaywoocommerce-payments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for WooCommerce – Helcim Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for WooCommerce – Helcim has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the static analysis, this plugin appears to have a generally good security posture. The absence of detected dangerous functions, raw SQL queries, and file operations are positive indicators. The presence of an external HTTP request, while not inherently a vulnerability, warrants attention for potential information disclosure or dependency issues if not properly secured. The fact that there are no detected taint flows and a clean vulnerability history is a significant strength, suggesting a commitment to secure coding practices and timely patching by the developers.

However, the complete lack of any detected capability checks or nonce checks on entry points (AJAX, REST API, shortcodes, cron) is a major concern. This indicates that potentially sensitive actions or data could be accessed or manipulated by unauthenticated or unauthorized users. While the current attack surface is zero, if any new entry points are introduced in future versions without proper authentication and authorization, it would create immediate vulnerabilities.

In conclusion, the plugin demonstrates strengths in avoiding common pitfalls like raw SQL and dangerous functions. Its clean vulnerability history is also reassuring. Nevertheless, the absence of crucial security mechanisms like capability and nonce checks represents a significant weakness that could be exploited if any entry points are ever exposed. Future development should prioritize implementing these fundamental security controls.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
  • 50% of outputs not properly escaped
  • Presence of external HTTP request
Vulnerabilities
None known

Payment Gateway for WooCommerce – Helcim Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Payment Gateway for WooCommerce – Helcim Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for WooCommerce – Helcim Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped8 total outputs
Attack Surface

Payment Gateway for WooCommerce – Helcim Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwoocommerce_receipt_helcimclass-wc-gateway-helcim.php:63
actionwoocommerce_api_wc_gateway_helcimclass-wc-gateway-helcim.php:65
actionplugins_loadedindex.php:11
filterwoocommerce_payment_gatewaysindex.php:23
Maintenance & Trust

Payment Gateway for WooCommerce – Helcim Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedApr 27, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Payment Gateway for WooCommerce – Helcim Developer Profile

Helcim

2 plugins · 810 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for WooCommerce – Helcim

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-for-woocommerce-by-helcim/helcim.css/wp-content/plugins/payment-gateway-for-woocommerce-by-helcim/helcim_gateway.js
Script Paths
/wp-content/plugins/payment-gateway-for-woocommerce-by-helcim/helcim_gateway.js
Version Parameters
payment-gateway-for-woocommerce-by-helcim/helcim.css?ver=payment-gateway-for-woocommerce-by-helcim/helcim_gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
helcim-payment-form
Data Attributes
data-helcim-gateway-urldata-helcim-form-action
JS Globals
helcim_gateway_params
FAQ

Frequently Asked Questions about Payment Gateway for WooCommerce – Helcim