Payment Gateways by Shipping for WooCommerce Security & Risk Analysis

wordpress.org/plugins/payment-gateways-by-shipping-for-woocommerce

Set "enable for shipping methods" for WooCommerce payment gateways.

500 active installs v1.5.1 PHP + WP 4.4+ Updated Sep 12, 2025
ecommercepayment-gatewaypayment-gatewaysshippingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateways by Shipping for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateways by Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of "payment-gateways-by-shipping-for-woocommerce" v1.5.1 reveals an exceptionally clean attack surface. There are no apparent entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which is a significant strength. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, further bolstering its security posture. The absence of any recorded CVEs or historical vulnerabilities also suggests a mature and stable codebase.

However, there are minor concerns that warrant attention. The output escaping is only 50% proper, meaning some data might be rendered without adequate sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities if the unescaped output is user-controlled. Additionally, the complete absence of nonce and capability checks, while not directly exploitable due to the lack of entry points, represents a missed opportunity to implement robust access control and security measures that would be critical if any entry points were to be introduced in future versions. Overall, the plugin exhibits a strong security foundation, but the unescaped output is a specific area for improvement.

Key Concerns

  • Half of output is not properly escaped
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Payment Gateways by Shipping for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateways by Shipping for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Payment Gateways by Shipping for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterwoocommerce_available_payment_gatewaysincludes\class-alg-wc-pgbsm-core.php:37
actionwoocommerce_before_calculate_totalsincludes\class-alg-wc-pgbsm-core.php:45
actioninitincludes\class-alg-wc-pgbsm.php:78
actionbefore_woocommerce_initincludes\class-alg-wc-pgbsm.php:81
actioninitincludes\class-alg-wc-pgbsm.php:162
actioninitincludes\class-alg-wc-pgbsm.php:165
filterwoocommerce_get_settings_pagesincludes\class-alg-wc-pgbsm.php:168
actionadmin_initincludes\class-alg-wc-pgbsm.php:172
actionadmin_footerincludes\settings\class-alg-wc-pgbsm-settings-general.php:30
filterwoocommerce_get_sections_alg_wc_pgbsmincludes\settings\class-alg-wc-pgbsm-settings-section.php:40
actionadmin_noticesincludes\settings\class-alg-wc-settings-pgbsm.php:83
actionplugins_loadedpayment-gateways-by-shipping-for-woocommerce.php:58
Maintenance & Trust

Payment Gateways by Shipping for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 12, 2025
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings3
Active installs500
Developer Profile

Payment Gateways by Shipping for WooCommerce Developer Profile

WPFactory

63 plugins · 136K total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
90 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateways by Shipping for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-gateways-by-shipping-for-woocommerce/assets/css/alg-wc-pgbsm-admin.css/wp-content/plugins/payment-gateways-by-shipping-for-woocommerce/assets/js/alg-wc-pgbsm-admin.js
Script Paths
/wp-content/plugins/payment-gateways-by-shipping-for-woocommerce/assets/js/alg-wc-pgbsm-admin.js
Version Parameters
payment-gateways-by-shipping-for-woocommerce/assets/css/alg-wc-pgbsm-admin.css?ver=payment-gateways-by-shipping-for-woocommerce/assets/js/alg-wc-pgbsm-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
alg_wc_pgbsm
FAQ

Frequently Asked Questions about Payment Gateways by Shipping for WooCommerce