PAYCOMET for WooCommerce Security & Risk Analysis

wordpress.org/plugins/paytpv-for-woocommerce

Módulo de pago PAYCOMET para WooCommerce. Permite realizar pagos con tarjeta de crédito. PAYCOMET - Pasarela de pagos PCI-DSS Nivel 1 Multiplataforma

2K active installs v5.42 PHP 5.6+ WP 3.0.1+ Updated Dec 9, 2025
pasarela-de-pagopaymentpayment-gatewaysuscripcioneswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PAYCOMET for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

PAYCOMET for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The paytpv-for-woocommerce plugin version 5.42 exhibits a concerning security posture primarily due to significant issues with output escaping and unsanitized data flows. While the plugin reports zero AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks, and has no recorded CVEs, these positive aspects are overshadowed by the identified code signals and taint analysis. The extremely low rate of properly escaped output (6%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential risks where user-controlled data could be processed in an unsafe manner, possibly leading to code injection or other severe exploits.

The lack of recorded vulnerabilities in its history is a positive sign, but it should not be interpreted as a guarantee of future security, especially given the current code analysis findings. The plugin's strengths lie in its limited attack surface and the fact that the majority of its SQL queries utilize prepared statements. However, the substantial risk posed by the unescaped output and high-severity unsanitized data flows necessitates immediate attention and remediation. Without addressing these critical weaknesses, the plugin remains vulnerable to significant security threats.

Key Concerns

  • Low output escaping rate
  • High severity unsanitized flows
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

PAYCOMET for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PAYCOMET for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
33 prepared
Unescaped Output
188
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

85% prepared39 total queries

Output Escaping

6% escaped199 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
<my-cards> (template\myaccount\my-cards.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PAYCOMET for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionplugins_loadedgateway-paytpv.php:32
actionadmin_enqueue_scriptsgateway-paytpv.php:33
actionwp_enqueue_scriptsgateway-paytpv.php:34
actionwoocommerce_before_my_accountgateway-paytpv.php:36
actionbefore_woocommerce_initgateway-paytpv.php:42
actionwoocommerce_before_checkout_formgateway-paytpv.php:48
filterwoocommerce_payment_gatewaysgateway-paytpv.php:60
actionadmin_initgateway-paytpv.php:131
actionadmin_noticesgateway-paytpv.php:181
actionwoocommerce_blocks_loadedgateway-paytpv.php:199
actionwoocommerce_blocks_payment_method_type_registrationgateway-paytpv.php:226
actionwp_enqueue_scriptsinc\paycomet-instantcredit.php:8
filterscript_loader_taginc\paycomet-instantcredit.php:23
filterwoocommerce_available_payment_gatewaysinc\paycomet-instantcredit.php:32
actionwoocommerce_order_details_before_order_tableinc\thankyou.php:3
actionwoocommerce_order_details_after_order_tableinc\thankyou.php:4
actionwoocommerce_email_after_order_tableinc\thankyou.php:5
actionwppaytpv_upgrade_versioninc\upgrade.php:3
actionadmin_noticesinc\woocommerce-paytpv.php:125
filterwcs_resubscribe_order_createdinc\woocommerce-paytpv.php:129
actionwoocommerce_review_order_before_submitinc\woocommerce-paytpv.php:133
actionwoocommerce_pay_order_before_submitinc\woocommerce-paytpv.php:134
filterwoocommerce_pay_order_button_htmlinc\woocommerce-paytpv.php:135
actionwoocommerce_store_api_checkout_update_order_from_requestinc\woocommerce-paytpv.php:140
Maintenance & Trust

PAYCOMET for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version5.6
Downloads73K

Community Trust

Rating60/100
Number of ratings4
Active installs2K
Developer Profile

PAYCOMET for WooCommerce Developer Profile

PAYCOMET

1 plugin · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PAYCOMET for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paytpv-for-woocommerce/assets/css/paytpv-style.css/wp-content/plugins/paytpv-for-woocommerce/assets/js/paytpv-script.js/wp-content/plugins/paytpv-for-woocommerce/assets/js/paytpv-checkout.js
Script Paths
/wp-content/plugins/paytpv-for-woocommerce/assets/js/paytpv-script.js/wp-content/plugins/paytpv-for-woocommerce/assets/js/paytpv-checkout.js
Version Parameters
/wp-content/plugins/paytpv-for-woocommerce/assets/css/paytpv-style.css?ver=/wp-content/plugins/paytpv-for-woocommerce/assets/js/paytpv-script.js?ver=/wp-content/plugins/paytpv-for-woocommerce/assets/js/paytpv-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
paytpv-checkout-container
Data Attributes
data-paytpv-terminaldata-paytpv-apikey
JS Globals
paytpv_params
REST Endpoints
/wp-json/paytpv/v1/process-payment
FAQ

Frequently Asked Questions about PAYCOMET for WooCommerce