
Sampath bank payment gateway Security & Risk Analysis
wordpress.org/plugins/sampath-bank-ipgWooCommerce Sampath bank payment gateway. Make your online payments via Sampath bank.
Is Sampath bank payment gateway Safe to Use in 2026?
Generally Safe
Score 85/100Sampath bank payment gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sampath-bank-ipg" plugin v1.0 exhibits a seemingly clean security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a reported zero vulnerabilities in its history suggests a degree of development maturity or lack of publicly disclosed issues. Furthermore, the static analysis indicates a remarkably small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. This is a significant strength, as it limits the potential entry points for attackers.
However, the code analysis reveals several concerning weaknesses that significantly undermine the plugin's overall security. A critical finding is the presence of a single SQL query that is not using prepared statements, indicating a high risk of SQL injection vulnerabilities. Additionally, all five identified output operations lack proper escaping, leaving the plugin susceptible to Cross-Site Scripting (XSS) attacks. The complete absence of nonce and capability checks on any potential entry points, coupled with the lack of authentication checks on AJAX handlers (even though there are none reported), points to a fundamental deficiency in securing the plugin's operations. While the attack surface is small, the unprotected nature of any potential future additions or the underlying functionality could be highly problematic.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and a minimal attack surface, the identified issues with raw SQL queries and unescaped output represent significant and exploitable risks. The absence of robust security checks like nonces and capability checks further exacerbates these concerns. Developers should prioritize addressing the SQL injection and XSS vulnerabilities immediately and implement proper authentication and authorization mechanisms.
Key Concerns
- Raw SQL query without prepared statements
- All outputs unescaped
- No nonce checks
- No capability checks
Sampath bank payment gateway Security Vulnerabilities
Sampath bank payment gateway Code Analysis
SQL Query Safety
Output Escaping
Sampath bank payment gateway Attack Surface
WordPress Hooks 5
Maintenance & Trust
Sampath bank payment gateway Maintenance & Trust
Maintenance Signals
Community Trust
Sampath bank payment gateway Alternatives
Sampath Bank Paycorp payment gateway
redevoke-sampath-paycorp-payment-gateway-paycorp
Accept all internationally acceptable credit card payments on your WooCommerce store with Sampath paycorp payment gateway
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Sampath bank payment gateway Developer Profile
8 plugins · 190 total installs
How We Detect Sampath bank payment gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sampath-bank-ipg/sampath.jpgHTML / DOM Fingerprints
<!-- Sampath bank online payment gateway -->data-merchant_iddata-pg_instance_iddata-performdata-currency_codedata-hash_keydata-sucess_responce_code+4 more