Skeps Pay-Over-Time Security & Risk Analysis

wordpress.org/plugins/skeps-pay-over-time

Skeps provides Pay-Over-Time options with monthly payment plans including no interest promos.

0 active installs v1.1 PHP + WP 3.2+ Updated Feb 22, 2024
buy-now-pay-later-bnplinstallment-loanspay-over-timepayment-solutionspos-financing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Skeps Pay-Over-Time Safe to Use in 2026?

Generally Safe

Score 85/100

Skeps Pay-Over-Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The skeps-pay-over-time v1.1 plugin exhibits a generally strong security posture based on the static analysis. The complete absence of an attack surface, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly reduces the potential entry points for attackers. The code also demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output, indicating a low risk of direct SQL injection or cross-site scripting vulnerabilities originating from these areas. The presence of nonce and capability checks, while limited, shows an awareness of basic security mechanisms.

Key Concerns

  • Bundled outdated library: Guzzle v1.1
  • External HTTP requests (2) without explicit security context
  • Limited capability checks (1)
Vulnerabilities
None known

Skeps Pay-Over-Time Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Skeps Pay-Over-Time Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
73 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle1.1

Output Escaping

94% escaped78 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
custom_bulk_admin_notices (class-woocommerce-gateway-skeps-financing.php:382)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Skeps Pay-Over-Time Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionplugins_loadedclass-woocommerce-gateway-skeps-financing.php:92
actionwoocommerce_order_refundedclass-woocommerce-gateway-skeps-financing.php:98
actionwoocommerce_order_partially_refundedclass-woocommerce-gateway-skeps-financing.php:103
actionwp_headclass-woocommerce-gateway-skeps-financing.php:109
actionwp_enqueue_scriptsclass-woocommerce-gateway-skeps-financing.php:113
actionwoocommerce_after_shop_loop_itemclass-woocommerce-gateway-skeps-financing.php:118
actionwoocommerce_single_product_summaryclass-woocommerce-gateway-skeps-financing.php:123
actionwoocommerce_after_add_to_cart_formclass-woocommerce-gateway-skeps-financing.php:128
actionwoocommerce_cart_totals_after_order_totalclass-woocommerce-gateway-skeps-financing.php:133
filterwoocommerce_available_payment_gatewaysclass-woocommerce-gateway-skeps-financing.php:139
filterwoocommerce_gateway_descriptionclass-woocommerce-gateway-skeps-financing.php:145
filterwoocommerce_payment_gatewaysclass-woocommerce-gateway-skeps-financing.php:168
actionwoocommerce_review_order_before_paymentincludes\class-wc-gateway-skeps-financing.php:114
actionwp_enqueue_scriptsincludes\class-wc-gateway-skeps-financing.php:119
Maintenance & Trust

Skeps Pay-Over-Time Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedFeb 22, 2024
PHP min version
Downloads555

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Skeps Pay-Over-Time Developer Profile

skepsdev

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Skeps Pay-Over-Time

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skeps-pay-over-time/build/skeps-bnpl.css/wp-content/plugins/skeps-pay-over-time/build/skeps-bnpl.js
Script Paths
/wp-content/plugins/skeps-pay-over-time/build/skeps-bnpl.js
Version Parameters
skeps-bnpl.css?ver=skeps-bnpl.js?ver=

HTML / DOM Fingerprints

CSS Classes
skeps-financing-promoskeps-bnpl-financing-promo
Data Attributes
data-skeps-bnpl-financing
JS Globals
skeps_bnpl_settings
FAQ

Frequently Asked Questions about Skeps Pay-Over-Time