SindiPay Payment Gateway Security & Risk Analysis

wordpress.org/plugins/sindipay-payment-gateway

Official SindiPay payment gateway for WooCommerce. Accept Iraqi bank cards including Qi Card. Perfect for businesses in Iraq!

0 active installs v1.0.1 PHP 7.2+ WP 5.0+ Updated Dec 6, 2025
gatewayiraqi-paymentspaymentqi-cardwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SindiPay Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

SindiPay Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "sindipay-payment-gateway" plugin version 1.0.1 exhibits a generally good security posture based on the static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events indicates a minimal attack surface. Furthermore, the code signals show no dangerous functions, all SQL queries use prepared statements, and file operations are absent, which are all positive security indicators. The low percentage of unescaped outputs (9%) is also reassuring. However, the plugin makes two external HTTP requests, which, without further context on their destination and purpose, could represent a potential risk if the target endpoints are compromised or susceptible to man-in-the-middle attacks.

The vulnerability history shows no recorded CVEs, which is a strong positive sign suggesting a lack of known, exploited, or historically problematic security flaws. This, combined with the clean taint analysis results (no unsanitized paths, no critical or high severity flows), reinforces the impression of a well-secured piece of code. While the plugin adheres to many secure coding practices, the lack of capability checks and nonce checks across any potential entry points (even though the static analysis reports zero entry points) warrants a cautious approach. Without these checks, if new entry points were inadvertently introduced in future versions, they could be vulnerable to unauthorized access or actions.

Key Concerns

  • External HTTP requests made
  • No capability checks
  • No nonce checks
  • Unescaped outputs present
Vulnerabilities
None known

SindiPay Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SindiPay Payment Gateway Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

SindiPay Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

91% escaped11 total outputs
Attack Surface

SindiPay Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwoocommerce_blocks_payment_method_type_registrationincludes\class-sindipay-blocks.php:79
actionadmin_noticesincludes\class-sindipay-gateway.php:53
actionbefore_woocommerce_initsindipay-gateway.php:30
actionplugins_loadedsindipay-gateway.php:45
actionadmin_noticessindipay-gateway.php:50
filterwoocommerce_payment_gatewayssindipay-gateway.php:64
actionwoocommerce_blocks_loadedsindipay-gateway.php:70
Maintenance & Trust

SindiPay Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 6, 2025
PHP min version7.2
Downloads218

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SindiPay Payment Gateway Developer Profile

sindipay

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SindiPay Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sindipay-payment-gateway/assets/css/sindipay-checkout.css/wp-content/plugins/sindipay-payment-gateway/assets/js/sindipay-checkout.js
Script Paths
/wp-content/plugins/sindipay-payment-gateway/assets/js/sindipay-checkout.js
Version Parameters
sindipay-payment-gateway/assets/css/sindipay-checkout.css?ver=sindipay-payment-gateway/assets/js/sindipay-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
sindipay-payment-gateway-noticesindipay_gateway
Data Attributes
data-gateway-id="sindipay"
REST Endpoints
/wp-json/sindipay/v1/process_payment
FAQ

Frequently Asked Questions about SindiPay Payment Gateway