SanalPosPRO Payment Gateway Security & Risk Analysis

wordpress.org/plugins/sanalpospro-payment-module

SanalPosPRO is a payment gateway integration plugin that provides secure and easy payment solution developed for WooCommerce.

200 active installs v10.0.4 PHP 7.4+ WP 5.8+ Updated Feb 19, 2026
odemeucretsizpossanal-poswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SanalPosPRO Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

SanalPosPRO Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'sanalpospro-payment-module' v10.0.4 exhibits a strong security posture based on the provided static analysis. It has a small attack surface, with all entry points protected by appropriate checks. The code demonstrates excellent security practices, with 100% of SQL queries using prepared statements and a very high percentage of output correctly escaped. Crucially, there are no detected dangerous functions, file operations, or external HTTP requests, and all identified AJAX handlers include nonce checks. The lack of any recorded vulnerabilities or CVEs in its history further reinforces this positive assessment, suggesting a commitment to secure development and maintenance. While the absence of taint analysis data is a minor point of interest, the overall evidence points to a robustly secured plugin with no immediate exploitable risks.

Vulnerabilities
None known

SanalPosPRO Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SanalPosPRO Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
53 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped57 total outputs
Attack Surface

SanalPosPRO Payment Gateway Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_sppro_internal_api_requestsanalpospro.php:46
noprivwp_ajax_sppro_internal_api_requestsanalpospro.php:47
WordPress Hooks 17
actionadmin_menuadmin\class-admin.php:10
actionadmin_enqueue_scriptsadmin\class-admin.php:12
filterscript_loader_tagadmin\class-admin.php:105
actionplugins_loadedsanalpospro.php:42
actionplugins_loadedsanalpospro.php:43
actionwoocommerce_blocks_loadedsanalpospro.php:44
actionwp_footersanalpospro.php:45
actionwp_enqueue_scriptssanalpospro.php:48
actionadmin_enqueue_scriptssanalpospro.php:49
actionwoocommerce_blocks_payment_method_type_registrationsanalpospro.php:71
actionadmin_noticessanalpospro.php:111
actionadmin_footersanalpospro.php:121
actionwp_enqueue_scriptssanalpospro.php:284
filterwp_kses_allowed_htmlsanalpospro.php:286
actionwoocommerce_admin_order_data_after_billing_addresssanalpospro.php:291
filterwoocommerce_product_tabssanalpospro.php:626
filterwoocommerce_payment_gatewayssanalpospro.php:676
Maintenance & Trust

SanalPosPRO Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

SanalPosPRO Payment Gateway Developer Profile

EticSoft AS

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SanalPosPRO Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sanalpospro-payment-module/assets/css/admin-popup.css/wp-content/plugins/sanalpospro-payment-module/assets/js/admin-popup.js
Script Paths
/wp-content/plugins/sanalpospro-payment-module/assets/js/admin-popup.js
Version Parameters
sanalpospro-payment-module?ver=admin-popup.css?ver=admin-popup.js?ver=

HTML / DOM Fingerprints

CSS Classes
sppro-noticesppro-popup-overlaysppro-popup-contentsppro-popup-closesppro-popup-titlesppro-notice
HTML Comments
<!-- ini_set('display_errors', 1); --><!-- ini_set('display_startup_errors', 1); --><!-- error_reporting(E_ALL); --><!-- Using proper WordPress way to display an image -->
Data Attributes
id="sppro-popup"id="sppro-show-instructions"
JS Globals
sppro_internal_api_request
FAQ

Frequently Asked Questions about SanalPosPRO Payment Gateway