
Payment Gateways by Shipping for WooCommerce Security & Risk Analysis
wordpress.org/plugins/payment-gateways-by-shipping-for-woocommerceSet "enable for shipping methods" for WooCommerce payment gateways.
Is Payment Gateways by Shipping for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Payment Gateways by Shipping for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "payment-gateways-by-shipping-for-woocommerce" v1.5.1 reveals an exceptionally clean attack surface. There are no apparent entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which is a significant strength. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, further bolstering its security posture. The absence of any recorded CVEs or historical vulnerabilities also suggests a mature and stable codebase.
However, there are minor concerns that warrant attention. The output escaping is only 50% proper, meaning some data might be rendered without adequate sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities if the unescaped output is user-controlled. Additionally, the complete absence of nonce and capability checks, while not directly exploitable due to the lack of entry points, represents a missed opportunity to implement robust access control and security measures that would be critical if any entry points were to be introduced in future versions. Overall, the plugin exhibits a strong security foundation, but the unescaped output is a specific area for improvement.
Key Concerns
- Half of output is not properly escaped
- No nonce checks implemented
- No capability checks implemented
Payment Gateways by Shipping for WooCommerce Security Vulnerabilities
Payment Gateways by Shipping for WooCommerce Code Analysis
Output Escaping
Payment Gateways by Shipping for WooCommerce Attack Surface
WordPress Hooks 12
Maintenance & Trust
Payment Gateways by Shipping for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Payment Gateways by Shipping for WooCommerce Alternatives
Conditional Payments and Shipping for WooCommerce
wc-restricted-shipping-and-payment
A simplistic plugin for excluding shipping methods based on multiple rules such as shipping class, package weight and cart totals.
Codiepress WooCommerce Conditional Shipping and Payments – Hide Shipping & Payment Methods
conditional-shipping-and-payments-for-woocommerce
Easily manage WooCommerce shipping & payment methods by cart, user roles, address & more. Enhance checkout with conditional shipping & payments.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pay for Payment for WooCommerce
woocommerce-pay-for-payment
Setup individual charges for each payment method in WooCommerce.
Payment Gateways by Shipping for WooCommerce Developer Profile
63 plugins · 136K total installs
How We Detect Payment Gateways by Shipping for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/payment-gateways-by-shipping-for-woocommerce/assets/css/alg-wc-pgbsm-admin.css/wp-content/plugins/payment-gateways-by-shipping-for-woocommerce/assets/js/alg-wc-pgbsm-admin.js/wp-content/plugins/payment-gateways-by-shipping-for-woocommerce/assets/js/alg-wc-pgbsm-admin.jspayment-gateways-by-shipping-for-woocommerce/assets/css/alg-wc-pgbsm-admin.css?ver=payment-gateways-by-shipping-for-woocommerce/assets/js/alg-wc-pgbsm-admin.js?ver=HTML / DOM Fingerprints
alg_wc_pgbsm