Zip US Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/quadpay-gateway-for-woocommerce

Use Zip US as a payment gateway for WooCommerce.

100 active installs v1.9.0 PHP 7.0+ WP 4.7+ Updated Aug 16, 2024
bnplgatewaypaymentwoocommercezip
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Zip US Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Zip US Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "quadpay-gateway-for-woocommerce" v1.9.0 plugin exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) and the static analysis revealed no critical or high severity taint flows, nor are there any dangerous functions or file operations. All SQL queries are properly prepared, which is an excellent practice. However, significant concerns arise from the complete lack of output escaping. With 29 outputs, none are properly escaped, leaving the plugin highly vulnerable to cross-site scripting (XSS) attacks where malicious scripts could be injected and executed in the user's browser.

Furthermore, the absence of nonce checks and capability checks across the plugin's code, coupled with 0 AJAX handlers and REST API routes that have permission callbacks, raises a red flag. While the static analysis reports no unprotected entry points, the lack of these fundamental security mechanisms suggests that even if entry points exist, they might not be adequately protected against unauthorized access or manipulation. The plugin also makes 8 external HTTP requests, which, without further context or analysis, could potentially be exploited if not handled securely. The vulnerability history being completely clean is a positive indicator, but it does not mitigate the immediate risks identified in the code analysis.

Key Concerns

  • Output escaping is 0% properly escaped
  • 0 Nonce checks found
  • 0 Capability checks found
  • 8 External HTTP requests made
Vulnerabilities
None known

Zip US Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zip US Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

0% escaped29 total outputs
Attack Surface

Zip US Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionwoocommerce_thankyouincludes\class-quadpay-gateway.php:88
actionwoocommerce_update_options_checkoutincludes\class-quadpay-gateway.php:90
actionwoocommerce_order_status_changedincludes\class-quadpay-gateway.php:92
actionwoocommerce_order_status_changedincludes\class-quadpay-gateway.php:93
actionwoocommerce_checkout_update_order_reviewincludes\class-quadpay-mfpp.php:29
actionwoocommerce_after_calculate_totalsincludes\class-quadpay-mfpp.php:30
actionwp_enqueue_scriptsincludes\class-quadpay-mfpp.php:31
actiontemplate_redirectincludes\class-quadpay-mfpp.php:43
filterwoocommerce_get_price_htmlincludes\class-quadpay-widget.php:45
filterwoocommerce_variable_price_htmlincludes\class-quadpay-widget.php:46
actionwoocommerce_proceed_to_checkoutincludes\class-quadpay-widget.php:47
actionwp_enqueue_scriptsincludes\class-quadpay-widget.php:48
filterwoocommerce_payment_gatewaysquadpay.php:40
actiontemplate_redirectquadpay.php:67
actionquadpay_thirty_minutes_cron_jobsquadpay.php:76
actionquadpay_four_times_daily_cron_jobsquadpay.php:85
filterwoocommerce_order_actionsquadpay.php:120
actionwoocommerce_order_action_check_quadpay_statusquadpay.php:155
actionplugins_loadedquadpay.php:162
actionwoocommerce_blocks_payment_method_type_registrationquadpay.php:170
actionwoocommerce_blocks_loadedquadpay.php:178
actionbefore_woocommerce_initquadpay.php:192
actionwpquadpay.php:214
filtercron_schedulesquadpay.php:254

Scheduled Events 3

quadpay_thirty_minutes_cron_jobs
quadpay_forty_five_minutes_cron_jobs
quadpay_four_times_daily_cron_jobs
Maintenance & Trust

Zip US Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 16, 2024
PHP min version7.0
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Zip US Gateway for WooCommerce Developer Profile

Zip Co US, Inc

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zip US Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quadpay-gateway-for-woocommerce/assets/css/quadpay.css/wp-content/plugins/quadpay-gateway-for-woocommerce/assets/js/quadpay.js
Script Paths
/wp-content/plugins/quadpay-gateway-for-woocommerce/assets/js/quadpay.js
Version Parameters
quadpay-gateway-for-woocommerce/assets/css/quadpay.css?ver=quadpay-gateway-for-woocommerce/assets/js/quadpay.js?ver=

HTML / DOM Fingerprints

CSS Classes
quadpay-checkout-modalquadpay-modal-contentquadpay-terms-wrapper
HTML Comments
<!-- quadpay_wc_blocks --><!-- Declare support for WooCommerce HPOS feature --><!-- WP-Cron activation and schedule setup -->
Data Attributes
data-quadpay-checkout-urldata-quadpay-modal-title
JS Globals
window.QuadPay
FAQ

Frequently Asked Questions about Zip US Gateway for WooCommerce