SagePay Server Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/sagepay-server-gateway-for-woocommerce

SagePay Server Gateway for accepting payments on your WooCommerce Store.

80 active installs v1.1.3 PHP + WP 4.5+ Updated Jul 30, 2021
ecommercepayment-gatewaysagepay-gosagepay-serverwoocommerce
85
A · Safe
CVEs total1
Unpatched0
Last CVEDec 17, 2017
Safety Verdict

Is SagePay Server Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

SagePay Server Gateway for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 17, 2017Updated 4yr ago
Risk Assessment

The plugin "sagepay-server-gateway-for-woocommerce" v1.1.3 exhibits a mixed security posture. On the positive side, static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations, indicating good practices in these areas. However, there are notable concerns. Half of the output operations are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The presence of an external HTTP request, while not inherently bad, can be a vector for attacks if not handled securely. The lack of nonce checks and capability checks on all entry points (though the entry points are few) is a weakness, as it bypasses standard WordPress security mechanisms for protecting actions and data. The vulnerability history shows a past XSS vulnerability, and while it is currently patched, it suggests a prior weakness in output sanitization or input validation. The absence of currently unpatched vulnerabilities is a positive sign, but the past incident and the identified output escaping issues warrant caution.

Key Concerns

  • Unescaped output (50% of 8)
  • External HTTP request (potential risk)
  • No nonce checks
  • No capability checks
  • Past XSS vulnerability history
Vulnerabilities
1

SagePay Server Gateway for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2017
2017
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2018-5316medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SagePay Server Gateway for WooCommerce < 1.0.9 - Cross-Site Scripting

Dec 17, 2017 Patched in 1.0.9 (2228d)
Code Analysis
Analyzed Mar 16, 2026

SagePay Server Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped8 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<redirect> (includes\pages\redirect.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SagePay Server Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedwoosagepayserver.php:22
actioninitwoosagepayserver.php:76
actionwoocommerce_api_woocommerce_sagepayserverwoosagepayserver.php:77
actionwoocommerce_receipt_sagepayserverwoosagepayserver.php:78
actionwoocommerce_update_options_payment_gatewayswoosagepayserver.php:79
filterwoocommerce_payment_gatewayswoosagepayserver.php:569
Maintenance & Trust

SagePay Server Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 30, 2021
PHP min version
Downloads8K

Community Trust

Rating46/100
Number of ratings3
Active installs80
Developer Profile

SagePay Server Gateway for WooCommerce Developer Profile

PatSaTECH

9 plugins · 400 total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
2228 days
View full developer profile
Detection Fingerprints

How We Detect SagePay Server Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sagepay-server-gateway-for-woocommerce/css/sagepay-server-gateway.css/wp-content/plugins/sagepay-server-gateway-for-woocommerce/js/sagepay-server-gateway.js
Script Paths
/wp-content/plugins/sagepay-server-gateway-for-woocommerce/js/sagepay-server-gateway.js
Version Parameters
sagepay-server-gateway-for-woocommerce/css/sagepay-server-gateway.css?ver=sagepay-server-gateway-for-woocommerce/js/sagepay-server-gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
sagepay-server-gateway-checkout
Data Attributes
data-gateway-urldata-vendor-namedata-modedata-transaction-typedata-payment-pagedata-iframe-enabled
JS Globals
sagepayServerGatewaySettings
FAQ

Frequently Asked Questions about SagePay Server Gateway for WooCommerce