Payment Gateway via Valitor for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payment-gateway-via-valitor-for-woocommerce

Get paid via Valitor in your woocommerce shop.

200 active installs v1.9.39 PHP + WP 4.4+ Updated Dec 11, 2025
credit-cardgatewayvalitorwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Payment Gateway via Valitor for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway via Valitor for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of "payment-gateway-via-valitor-for-woocommerce" v1.9.39 reveals a generally strong security posture. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected, and no dangerous functions or file operations are utilized. All SQL queries employ prepared statements, which is a significant security advantage. However, a notable concern is the relatively low percentage (75%) of properly escaped output, suggesting a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are dynamic and user-controllable.

The absence of any recorded CVEs and the clean taint analysis indicate a history of good security practices or a lack of discovery of exploitable flaws. The plugin's attack surface is minimal and appears to be well-protected. The lack of nonce checks and capability checks on entry points is not explicitly concerning given that there are no identified entry points. The main area for improvement lies in ensuring all output is rigorously escaped to mitigate any potential XSS risks.

Overall, the plugin demonstrates a good foundation for security with a minimal attack surface and secure database interactions. The primary weakness identified is the potential for XSS due to incomplete output escaping. The vulnerability history is clean, which is a positive sign, but the unescaped output remains a point of caution that warrants attention.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Payment Gateway via Valitor for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway via Valitor for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped16 total outputs
Attack Surface

Payment Gateway via Valitor for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterwcml_gateway_text_keys_to_translateincludes\class-wc-gateway-valitor.php:140
actionwoocommerce_api_wc_gateway_valitorincludes\class-wc-gateway-valitor.php:147
actionwoocommerce_thankyouincludes\class-wc-gateway-valitor.php:148
actionadmin_noticesincludes\class-wc-gateway-valitor.php:768
actionbefore_woocommerce_initvalitor.php:24
actionplugins_loadedvalitor.php:33
filterwoocommerce_payment_gatewaysvalitor.php:41
actionwoocommerce_cancelled_ordervalitor.php:48
actionplugins_loadedvalitor.php:65
actionwoocommerce_blocks_loadedvalitor.php:104
actionwoocommerce_blocks_payment_method_type_registrationvalitor.php:109
actionwoocommerce_blocks_checkout_enqueue_datavalitor.php:118
Maintenance & Trust

Payment Gateway via Valitor for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Payment Gateway via Valitor for WooCommerce Developer Profile

tacticaisdev

2 plugins · 300 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway via Valitor for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateway-via-valitor-for-woocommerce/cards.png
Version Parameters
payment-gateway-via-valitor-for-woocommerce/cards.png?ver=valitor-styles-frontend

HTML / DOM Fingerprints

CSS Classes
valitor_woocommerce
Data Attributes
data-valitor-payment
JS Globals
valitor_woocommerce_params
FAQ

Frequently Asked Questions about Payment Gateway via Valitor for WooCommerce