Payssion Plugin for Woocommerce Security & Risk Analysis

wordpress.org/plugins/payssion-international-payment-gateway

Official Payssion module for WordPress WooCommerce.

300 active installs v1.3.1 PHP + WP 4.0+ Updated Jan 16, 2026
ecommercepaymentpaymentgatewaysofortbankingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payssion Plugin for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payssion Plugin for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "payssion-international-payment-gateway" plugin version 1.3.1 exhibits a mixed security posture. While there are no recorded historical vulnerabilities and the code demonstrates a complete absence of dangerous functions and external HTTP requests, several areas of concern are highlighted by the static analysis. The plugin has a zero attack surface, meaning no publicly accessible AJAX handlers, REST API routes, shortcodes, or cron events are present, which is a significant positive security indicator. Furthermore, all SQL queries utilize prepared statements, mitigating the risk of SQL injection. However, the taint analysis reveals a concerning "flow with unsanitized paths" of high severity, indicating a potential for attackers to inject malicious data that is not properly validated or cleaned. Additionally, the output escaping is only 39% properly done, suggesting that sensitive data displayed to users might be vulnerable to cross-site scripting (XSS) attacks. The lack of nonce and capability checks across any potential entry points (though none were identified) is also a noteworthy weakness, as it leaves room for unexpected vulnerabilities if the attack surface were to expand or change.

Key Concerns

  • High severity taint flow with unsanitized path
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Payssion Plugin for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payssion Plugin for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

39% escaped18 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-wc-gateway-payssion-notify-handler> (includes\class-wc-gateway-payssion-notify-handler.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payssion Plugin for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_api_wc_gateway_payssionincludes\class-wc-gateway-payssion-notify-handler.php:18
actionvalid-payssion-notifyincludes\class-wc-gateway-payssion-notify-handler.php:19
actionplugins_loadedpayssion.php:11
filterwoocommerce_payment_gatewayspayssion.php:323
actioninitpayssion.php:347
filterwc_order_statusespayssion.php:352
Maintenance & Trust

Payssion Plugin for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 16, 2026
PHP min version
Downloads16K

Community Trust

Rating66/100
Number of ratings12
Active installs300
Developer Profile

Payssion Plugin for Woocommerce Developer Profile

payssion

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payssion Plugin for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payssion-international-payment-gateway/payssion.css/wp-content/plugins/payssion-international-payment-gateway/payssion.js
Script Paths
/wp-content/plugins/payssion-international-payment-gateway/payssion.js
Version Parameters
payssion-international-payment-gateway/payssion.css?ver=payssion-international-payment-gateway/payssion.js?ver=

HTML / DOM Fingerprints

CSS Classes
payssion-checkout-logopayssion-payment-itempayssion-payment-logo
HTML Comments
This is the main file for the Payssion Payment Gateway plugin.
Data Attributes
data-payssion-checkout-url
JS Globals
payssion_checkout_url
FAQ

Frequently Asked Questions about Payssion Plugin for Woocommerce