Sama Payment Gateway Security & Risk Analysis

wordpress.org/plugins/sama-payment-gateway

درگاه پرداخت تضمین شده سامانه معاملات امن ایران (سما)

80 active installs v1.1.2 PHP 7.4+ WP 6.0.0+ Updated Feb 21, 2024
farsiiranpersiansamawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sama Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Sama Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "sama-payment-gateway" v1.1.2 plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, fully prepared SQL statements, and properly escaped output are strong indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerability history, which suggests a history of stability and security. The plugin also avoids common attack vectors like shortcodes, cron events, and unprotected AJAX/REST API endpoints, significantly reducing its attack surface.

However, there are a couple of areas that warrant attention. The presence of two taint flows with unsanitized paths, even without critical or high severity, indicates potential for vulnerabilities if user-supplied data is not handled rigorously. While the severity is not specified, unsanitized paths are a common precursor to various injection vulnerabilities. Additionally, the plugin performs four external HTTP requests without any mention of authentication or capability checks for these operations, which could expose the site to risks if these external services are compromised or if the requests themselves are not secured.

In conclusion, the plugin has a solid foundation with many security best practices implemented. The lack of known vulnerabilities is reassuring. The primary areas for concern are the unsanitized taint flows and the potentially unauthenticated external HTTP requests. Addressing these would further strengthen the plugin's security and provide greater peace of mind for users.

Key Concerns

  • Unsanitized paths in taint flows
  • External HTTP requests without auth checks implied
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Sama Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sama Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
sama_checkout_return_handler (class-gateway.php:284)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sama Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedaction.php:3
filterwoocommerce_payment_gatewaysaction.php:6
filterwoocommerce_currenciesaction.php:13
filterwoocommerce_currency_symbolaction.php:23
actionwoocommerce_update_options_payment_gatewaysclass-gateway.php:48
Maintenance & Trust

Sama Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 21, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Sama Payment Gateway Developer Profile

Sama.ir

1 plugin · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sama Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sama-payment-gateway/assets/images/logo.png

HTML / DOM Fingerprints

JS Globals
WC_GSama_Gateway
REST Endpoints
/wp-json/wc-gsama/v1/gateway
FAQ

Frequently Asked Questions about Sama Payment Gateway