Paythru Payment Gateway Security & Risk Analysis

wordpress.org/plugins/paythru-payment-gateway

Paythru WooCommerce Payment Gateway allows you to accept online payments from local and international customers

0 active installs v1.0.0 PHP + WP 4.7+ Updated Jul 10, 2022
nigeriapayment-gatewaypaythruvervewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paythru Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Paythru Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "paythru-payment-gateway" v1.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of critical code signals like dangerous functions, unsanitized taint flows, raw SQL queries, and the presence of output escaping are all positive indicators. The limited attack surface and the fact that all identified entry points (though none are present) would theoretically be protected suggests good development practices. The lack of any recorded vulnerabilities, including critical or high severity ones, further reinforces this positive assessment.

However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current version might not expose obvious vulnerabilities due to a small attack surface and good coding hygiene, these missing checks represent potential weaknesses that could be exploited if any new entry points or insecure functionalities were introduced in future updates or if the plugin interacts with other components in unexpected ways. The presence of file operations and external HTTP requests, while not inherently problematic, are areas that require careful oversight as they can become vectors for attack if not properly secured and validated against user input.

In conclusion, the plugin demonstrates a commendable commitment to security by avoiding common pitfalls and maintaining a clean vulnerability history. The foundational code appears robust. Nevertheless, the omission of fundamental security checks like nonces and capability checks is a notable gap that introduces a degree of risk. Addressing these missing checks should be a priority to ensure a more resilient and secure plugin.

Key Concerns

  • Missing Nonce checks
  • Missing Capability checks
Vulnerabilities
None known

Paythru Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Paythru Payment Gateway Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Paythru Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Paythru Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwoocommerce_payment_gatewayspaythru.php:14
actionplugins_loadedpaythru.php:24
actionwoocommerce_api_callbackpaythru.php:70
Maintenance & Trust

Paythru Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.12
Last updatedJul 10, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Paythru Payment Gateway Developer Profile

pethahiah01

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paythru Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
translators: %s: set webhook url
REST Endpoints
/wc-api/callback
FAQ

Frequently Asked Questions about Paythru Payment Gateway