
Sama Payment Gateway Security & Risk Analysis
wordpress.org/plugins/sama-payment-gatewayدرگاه پرداخت تضمین شده سامانه معاملات امن ایران (سما)
Is Sama Payment Gateway Safe to Use in 2026?
Generally Safe
Score 85/100Sama Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sama-payment-gateway" v1.1.2 plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, fully prepared SQL statements, and properly escaped output are strong indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerability history, which suggests a history of stability and security. The plugin also avoids common attack vectors like shortcodes, cron events, and unprotected AJAX/REST API endpoints, significantly reducing its attack surface.
However, there are a couple of areas that warrant attention. The presence of two taint flows with unsanitized paths, even without critical or high severity, indicates potential for vulnerabilities if user-supplied data is not handled rigorously. While the severity is not specified, unsanitized paths are a common precursor to various injection vulnerabilities. Additionally, the plugin performs four external HTTP requests without any mention of authentication or capability checks for these operations, which could expose the site to risks if these external services are compromised or if the requests themselves are not secured.
In conclusion, the plugin has a solid foundation with many security best practices implemented. The lack of known vulnerabilities is reassuring. The primary areas for concern are the unsanitized taint flows and the potentially unauthenticated external HTTP requests. Addressing these would further strengthen the plugin's security and provide greater peace of mind for users.
Key Concerns
- Unsanitized paths in taint flows
- External HTTP requests without auth checks implied
- Missing nonce checks
- Missing capability checks
Sama Payment Gateway Security Vulnerabilities
Sama Payment Gateway Code Analysis
Output Escaping
Data Flow Analysis
Sama Payment Gateway Attack Surface
WordPress Hooks 5
Maintenance & Trust
Sama Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Sama Payment Gateway Alternatives
Gateway AqayePardakht for Woocommerce
gateway-aqayepardakht-for-woocommerce
با نصب این پلاگین می توانید از خدمات درگاه آقای پرداخت برای پلاگین ووکامرس استفاده کنید!
Persian Reports – گزارش فارسی ووکامرس
persian-reports
گزارش و آمار پیشرفته فروشگاه ووکامرس به فارسی و تاریخ شمسی ★★★★★
Iran Map
iran-map
Add minimal and nice iran map to your WordPress web site.
Month of Ramadan
month-of-ramadan
The plugin prayer during Ramadan.
نمایندگی نت سرویس
netservice-reseller
پلاگین نت سرویس برای نمایندگان رسمی
Sama Payment Gateway Developer Profile
1 plugin · 80 total installs
How We Detect Sama Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sama-payment-gateway/assets/images/logo.pngHTML / DOM Fingerprints
WC_GSama_Gateway/wp-json/wc-gsama/v1/gateway