
PatSaTECH's Opayo Direct Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/sagepay-direct-gateway-for-woocommercePatSaTECH's Opayo Direct Gateway for accepting payments on your WooCommerce Store.
Is PatSaTECH's Opayo Direct Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100PatSaTECH's Opayo Direct Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'sagepay-direct-gateway-for-woocommerce' plugin v1.3.1 reveals a generally strong security posture with no identified entry points that lack authentication or permission checks, nor any dangerous functions or SQL queries without prepared statements. The absence of file operations and bundled libraries is also positive. However, the analysis does indicate potential areas for improvement. A significant portion of output (27%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. Furthermore, the lack of nonce checks and capability checks on any potential handlers, while currently there are no handlers, represents a potential future risk if entry points are introduced without these essential security measures. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a proactive approach to security or a lack of past exploitation. Overall, the plugin demonstrates good security practices in its current state, but the unescaped output and the absence of fundamental security checks for potential future entry points warrant attention.
Key Concerns
- Significant unescaped output detected
- No nonce checks implemented
- No capability checks implemented
PatSaTECH's Opayo Direct Gateway for WooCommerce Security Vulnerabilities
PatSaTECH's Opayo Direct Gateway for WooCommerce Code Analysis
Output Escaping
PatSaTECH's Opayo Direct Gateway for WooCommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
PatSaTECH's Opayo Direct Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PatSaTECH's Opayo Direct Gateway for WooCommerce Alternatives
PatSaTECH's Opayo Server Gateway for WooCommerce
patsatech-wc-opayo-server
PatSaTECH's Opayo Server Gateway for accepting payments on your WooCommerce Store.
Opayo Direct Gateway for Gravity Forms
sagepay-direct-gateway-for-gravity-forms
Opayo Direct Gateway for accepting payments on your Gravity Forms.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pay for Payment for WooCommerce
woocommerce-pay-for-payment
Setup individual charges for each payment method in WooCommerce.
Bold pagos en linea
bold-pagos-en-linea
Recibe pagos en tu tienda de forma segura con diferentes métodos de pago confiables.
PatSaTECH's Opayo Direct Gateway for WooCommerce Developer Profile
9 plugins · 400 total installs
How We Detect PatSaTECH's Opayo Direct Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-amex.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-dc.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-delta.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-jcb.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-laser.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-maestro.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-mc.png/wp-content/plugins/sagepay-direct-gateway-for-woocommerce/images/card-uke.png+1 moreHTML / DOM Fingerprints
woocommerce_sagepaydirectname="sagepaydirect-card-type"name="sagepaydirect-card-name"/wp-json/woosagepaypatsatech/v1