
PlanetStudio Payment Gateway Security & Risk Analysis
wordpress.org/plugins/planetstudio-payment-gatewayAccept payments via Armenian banks and the Idram Wallet payment system.
Is PlanetStudio Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100PlanetStudio Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "planetstudio-payment-gateway" v1.1.8 plugin exhibits a generally strong security posture, with several positive indicators. The extensive use of prepared statements for all SQL queries and a very high percentage of properly escaped output are commendable. The plugin also demonstrates a good understanding of WordPress security best practices by implementing a significant number of nonce and capability checks across its functionalities, effectively limiting its attack surface. There are no known past vulnerabilities or CVEs, which suggests a history of secure development or diligent patching.
However, two specific concerns warrant attention. The presence of two "flows with unsanitized paths" in the taint analysis, despite not reaching critical or high severity, indicates a potential weakness in how file paths are handled. While these may not be exploitable without further conditions, they represent an area where an attacker could potentially manipulate file access. Furthermore, the plugin's reliance on 8 external HTTP requests could introduce risks if the target endpoints are compromised or if the plugin fails to properly validate responses from these external services.
Overall, the plugin is well-secured with robust input validation and authorization mechanisms. The identified unsanitized path flows are the primary area of concern and should be investigated for potential remediation. The lack of past vulnerabilities is a significant strength, but continuous vigilance regarding external dependencies and path handling is advised.
Key Concerns
- Flows with unsanitized paths detected
- 8 external HTTP requests
PlanetStudio Payment Gateway Security Vulnerabilities
PlanetStudio Payment Gateway Release Timeline
PlanetStudio Payment Gateway Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PlanetStudio Payment Gateway Attack Surface
AJAX Handlers 1
WordPress Hooks 49
Maintenance & Trust
PlanetStudio Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
PlanetStudio Payment Gateway Alternatives
Planet Studio Payment Gateway for ArCa
arca-payment-gateway
Accept payments from local & international customers to Armenian banks & Idram via ArCa paycenter for WooCommerce & GiveWP donation plugin.
Bayarcash for Fluent Forms
bayarcash-for-fluent-forms
Integrate Bayarcash payment gateway with Fluent Forms to accept payments in Malaysia via FPX, DuitNow, and other local payment methods.
Bayarcash for Gravity Forms
bayarcash-for-gravity-forms
Integrate Bayarcash payment gateway with Gravity Forms to accept payments in Malaysia via FPX, DuitNow, and other local payment methods.
Bayarcash For Easy Digital Downloads
bayarcash-for-easy-digital-downloads
Integrate Bayarcash payment solutions with your Easy Digital Downloads store.
Bayarcash for FluentCart
bayarcash-for-fluentcart
Accept payments via Bayarcash payment gateway for FluentCart. Supports FPX, DuitNow QR, and other Malaysian payment methods.
PlanetStudio Payment Gateway Developer Profile
3 plugins · 170 total installs
How We Detect PlanetStudio Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/planetstudio-payment-gateway/includes/assets/css/pspg-style.cssplanetstudio-payment-gateway/includes/assets/css/pspg-style.css?ver=planetstudio-payment-gatewayHTML / DOM Fingerprints
pspg-addon-license-boxpspg-addon-license-box--activepspg-addon-linkspspg-dotShared PayLink helper (currency + bank labels).Render built-in info box for PayLink / QR card.Show admin notice if supported plugins are detected but PSPG add-ons are not installed.Handle dismiss action for missing add-ons notice.+27 moredata-pspg-dismisspspg_core