
SagePay Server Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/sagepay-server-gateway-for-woocommerceSagePay Server Gateway for accepting payments on your WooCommerce Store.
Is SagePay Server Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100SagePay Server Gateway for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "sagepay-server-gateway-for-woocommerce" v1.1.3 exhibits a mixed security posture. On the positive side, static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations, indicating good practices in these areas. However, there are notable concerns. Half of the output operations are not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The presence of an external HTTP request, while not inherently bad, can be a vector for attacks if not handled securely. The lack of nonce checks and capability checks on all entry points (though the entry points are few) is a weakness, as it bypasses standard WordPress security mechanisms for protecting actions and data. The vulnerability history shows a past XSS vulnerability, and while it is currently patched, it suggests a prior weakness in output sanitization or input validation. The absence of currently unpatched vulnerabilities is a positive sign, but the past incident and the identified output escaping issues warrant caution.
Key Concerns
- Unescaped output (50% of 8)
- External HTTP request (potential risk)
- No nonce checks
- No capability checks
- Past XSS vulnerability history
SagePay Server Gateway for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SagePay Server Gateway for WooCommerce < 1.0.9 - Cross-Site Scripting
SagePay Server Gateway for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
SagePay Server Gateway for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
SagePay Server Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SagePay Server Gateway for WooCommerce Alternatives
SagePay Form Gateway for WooCommerce
sagepay-form-gateway-for-woocommerce
SagePay Form Gateway for accepting payments on your WooCommerce Store.
Accept SagePay Payments Using Contact Form 7
accept-sagepay-payments-using-contact-form-7
SagePay Server Gateway for accepting payments on your Contact Form 7.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pay for Payment for WooCommerce
woocommerce-pay-for-payment
Setup individual charges for each payment method in WooCommerce.
Bold pagos en linea
bold-pagos-en-linea
Recibe pagos en tu tienda de forma segura con diferentes métodos de pago confiables.
SagePay Server Gateway for WooCommerce Developer Profile
9 plugins · 400 total installs
How We Detect SagePay Server Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sagepay-server-gateway-for-woocommerce/css/sagepay-server-gateway.css/wp-content/plugins/sagepay-server-gateway-for-woocommerce/js/sagepay-server-gateway.js/wp-content/plugins/sagepay-server-gateway-for-woocommerce/js/sagepay-server-gateway.jssagepay-server-gateway-for-woocommerce/css/sagepay-server-gateway.css?ver=sagepay-server-gateway-for-woocommerce/js/sagepay-server-gateway.js?ver=HTML / DOM Fingerprints
sagepay-server-gateway-checkoutdata-gateway-urldata-vendor-namedata-modedata-transaction-typedata-payment-pagedata-iframe-enabledsagepayServerGatewaySettings