
Robokassa payment gateway with Subscriptions support Security & Risk Analysis
wordpress.org/plugins/robokassa-subscriptionsRobokassa сделала свой популярный модуль для WooCommerce еще лучше - теперь он поддерживает не только обычные продажи, но и функционал подписок, а так …
Is Robokassa payment gateway with Subscriptions support Safe to Use in 2026?
Generally Safe
Score 85/100Robokassa payment gateway with Subscriptions support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The robokassa-subscriptions plugin v1.1.5 exhibits a mixed security posture. While it has no recorded vulnerabilities and a seemingly limited attack surface in terms of direct entry points like AJAX, REST API, and shortcodes, the static analysis reveals significant areas of concern. A substantial portion of its SQL queries are not using prepared statements, and a worrying percentage of output operations are not properly escaped. This combination of raw SQL and unescaped output creates a heightened risk for SQL injection and cross-site scripting (XSS) vulnerabilities, even if no direct flows were flagged as critical in the taint analysis. The presence of unsanitized paths in taint flows further amplifies these risks.
Furthermore, the complete absence of nonce checks and capability checks across its components is a major security oversight. This means that actions, even those related to cron events, could potentially be triggered or manipulated by unauthenticated or unauthorized users. The plugin's vulnerability history being completely clear is a positive sign, but it cannot entirely mitigate the inherent risks identified within the code itself. A strong conclusion would be that while the plugin has not yet demonstrated exploitable vulnerabilities, its internal code quality and lack of fundamental security checks present a significant potential for future security incidents, particularly SQL injection and XSS.
Key Concerns
- Raw SQL queries present
- Unescaped output present
- No nonce checks
- No capability checks
- Unsanitized paths in taint flows
Robokassa payment gateway with Subscriptions support Security Vulnerabilities
Robokassa payment gateway with Subscriptions support Release Timeline
Robokassa payment gateway with Subscriptions support Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Robokassa payment gateway with Subscriptions support Attack Surface
WordPress Hooks 14
Scheduled Events 1
Maintenance & Trust
Robokassa payment gateway with Subscriptions support Maintenance & Trust
Maintenance Signals
Community Trust
Robokassa payment gateway with Subscriptions support Alternatives
Robokassa payment gateway for Woocommerce
robokassa
Позволяет использовать интерфейс (платежный шлюз) для оплаты через Робокассу в WooCommerce. Поддерживает интеграцию чеков (закон 54-ФЗ)
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Pay for Payment for WooCommerce
woocommerce-pay-for-payment
Setup individual charges for each payment method in WooCommerce.
Robokassa payment gateway with Subscriptions support Developer Profile
2 plugins · 3K total installs
How We Detect Robokassa payment gateway with Subscriptions support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/robokassa-subscriptions/assets/css/menu.css/wp-content/plugins/robokassa-subscriptions/assets/css/main.cssHTML / DOM Fingerprints
jQuery