
Robokassa payment gateway for Woocommerce Security & Risk Analysis
wordpress.org/plugins/robokassaПозволяет использовать интерфейс (платежный шлюз) для оплаты через Робокассу в WooCommerce. Поддерживает интеграцию чеков (закон 54-ФЗ)
Is Robokassa payment gateway for Woocommerce Safe to Use in 2026?
Mostly Safe
Score 75/100Robokassa payment gateway for Woocommerce is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The robokassa plugin version 1.8.5 presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, exclusively using prepared statements, and its taint analysis did not reveal any critical or high-severity vulnerabilities. The plugin also avoids bundling external libraries, which can often introduce vulnerabilities if not kept up-to-date.
However, significant concerns arise from the attack surface. With two AJAX handlers, both lacking authentication checks, this opens up potential avenues for unauthorized actions. Furthermore, the plugin has a history of known vulnerabilities, with one CVE still unpatched. The commonality of Cross-site Scripting (XSS) in past vulnerabilities, combined with a concerning 57% of outputs being not properly escaped, suggests a persistent weakness in input validation and output sanitization. The absence of nonce checks on AJAX actions is a critical oversight that directly correlates with XSS risks.
While the plugin doesn't exhibit severe code-level vulnerabilities in the current static analysis, the unpatched CVE, unprotected AJAX endpoints, and the history of XSS vulnerabilities, especially when coupled with insufficient output escaping and missing nonce checks, indicate a medium to high-risk profile. A proactive approach is needed to address the unpatched vulnerability and to secure the AJAX endpoints.
Key Concerns
- Unpatched CVE detected
- AJAX handlers without auth checks
- Missing nonce checks on AJAX
- Low percentage of properly escaped output
- Large attack surface without auth
Robokassa payment gateway for Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Robokassa payment gateway for Woocommerce <= 1.8.1 - Reflected Cross-Site Scripting
Robokassa payment gateway for Woocommerce <= 1.6.1 - Reflected Cross-Site Scripting
Robokassa payment gateway for Woocommerce <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Robokassa payment gateway for Woocommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Robokassa payment gateway for Woocommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 25
Scheduled Events 1
Maintenance & Trust
Robokassa payment gateway for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Robokassa payment gateway for Woocommerce Alternatives
Robokassa payment gateway with Subscriptions support
robokassa-subscriptions
Robokassa сделала свой популярный модуль для WooCommerce еще лучше - теперь он поддерживает не только обычные продажи, но и функционал подписок, а так …
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pay for Payment for WooCommerce
woocommerce-pay-for-payment
Setup individual charges for each payment method in WooCommerce.
Bold pagos en linea
bold-pagos-en-linea
Recibe pagos en tu tienda de forma segura con diferentes métodos de pago confiables.
Pay in Store WooCommerce Payment Gateway
pay-in-store-woocommerce-payment-gateway
Provides a Pay in Store upon pick up Payment Gateway for Woocommerce.
Robokassa payment gateway for Woocommerce Developer Profile
2 plugins · 3K total installs
How We Detect Robokassa payment gateway for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/robokassa/assets/css/robokassa-redirect.css/wp-content/plugins/robokassa/assets/js/robokassa-redirect.js/wp-content/plugins/robokassa/assets/js/robokassa-redirect.jsrobokassa-redirectHTML / DOM Fingerprints
robokassaRedirectConfig/wp-json/robokassa-payment/v1/settings