Robokassa payment gateway with Subscriptions support Security & Risk Analysis

wordpress.org/plugins/robokassa-subscriptions

Robokassa сделала свой популярный модуль для WooCommerce еще лучше - теперь он поддерживает не только обычные продажи, но и функционал подписок, а так …

40 active installs v1.1.5 PHP 5.6.32+ WP 5.7+ Updated Apr 11, 2023
ecommercepayment-gatewayrobokassarobokassa-payment-gatewaysubscriptions
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Robokassa payment gateway with Subscriptions support Safe to Use in 2026?

Generally Safe

Score 85/100

Robokassa payment gateway with Subscriptions support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The robokassa-subscriptions plugin v1.1.5 exhibits a mixed security posture. While it has no recorded vulnerabilities and a seemingly limited attack surface in terms of direct entry points like AJAX, REST API, and shortcodes, the static analysis reveals significant areas of concern. A substantial portion of its SQL queries are not using prepared statements, and a worrying percentage of output operations are not properly escaped. This combination of raw SQL and unescaped output creates a heightened risk for SQL injection and cross-site scripting (XSS) vulnerabilities, even if no direct flows were flagged as critical in the taint analysis. The presence of unsanitized paths in taint flows further amplifies these risks.

Furthermore, the complete absence of nonce checks and capability checks across its components is a major security oversight. This means that actions, even those related to cron events, could potentially be triggered or manipulated by unauthenticated or unauthorized users. The plugin's vulnerability history being completely clear is a positive sign, but it cannot entirely mitigate the inherent risks identified within the code itself. A strong conclusion would be that while the plugin has not yet demonstrated exploitable vulnerabilities, its internal code quality and lack of fundamental security checks present a significant potential for future security incidents, particularly SQL injection and XSS.

Key Concerns

  • Raw SQL queries present
  • Unescaped output present
  • No nonce checks
  • No capability checks
  • Unsanitized paths in taint flows
Vulnerabilities
None known

Robokassa payment gateway with Subscriptions support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Robokassa payment gateway with Subscriptions support Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Robokassa payment gateway with Subscriptions support Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
2 prepared
Unescaped Output
43
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
14
External Requests
5
Bundled Libraries
0

SQL Query Safety

18% prepared11 total queries

Output Escaping

19% escaped53 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
sendSms (classes\Robokassa\Payment\RobokassaPayAPI.php:357)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Robokassa payment gateway with Subscriptions support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_noticesclasses\Robokassa\Payment\WC_WP_robokassa.php:13
actionwp_enqueue_scriptswp_robokassa.php:17
actionwoocommerce_cart_calculate_feeswp_robokassa.php:40
actionwoocommerce_review_order_before_paymentwp_robokassa.php:67
actionadmin_menuwp_robokassa.php:82
actionplugins_loadedwp_robokassa.php:83
actionparse_requestwp_robokassa.php:84
actionparse_requestwp_robokassa.php:85
actionwoocommerce_order_status_completedwp_robokassa.php:86
filtercron_scheduleswp_robokassa.php:87
actionrobokassaCRON1wp_robokassa.php:88
actionwoocommerce_order_status_changedwp_robokassa.php:90
filterwoocommerce_get_privacy_policy_textwp_robokassa.php:98
filterwoocommerce_payment_gatewayswp_robokassa.php:874

Scheduled Events 1

robokassaCRON1
Maintenance & Trust

Robokassa payment gateway with Subscriptions support Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedApr 11, 2023
PHP min version5.6.32
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Robokassa payment gateway with Subscriptions support Developer Profile

robokassa

2 plugins · 3K total installs

65
trust score
Avg Security Score
80/100
Avg Patch Time
145 days
View full developer profile
Detection Fingerprints

How We Detect Robokassa payment gateway with Subscriptions support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/robokassa-subscriptions/assets/css/menu.css/wp-content/plugins/robokassa-subscriptions/assets/css/main.css

HTML / DOM Fingerprints

JS Globals
jQuery
FAQ

Frequently Asked Questions about Robokassa payment gateway with Subscriptions support