
SnapScan Payment Gateway Security & Risk Analysis
wordpress.org/plugins/snapscan-online-paymentsA free, safe, and secure payment integration where customers can pay via SnapScan or card with automatic WooCommerce payment reconciliation.
Is SnapScan Payment Gateway Safe to Use in 2026?
Generally Safe
Score 100/100SnapScan Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The snapscan-online-payments plugin v1.6.0 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a high percentage of properly escaped output. The absence of known vulnerabilities and a clean vulnerability history are also positive indicators. However, significant security concerns are raised by the static analysis results, particularly the substantial unprotected attack surface. All three identified REST API routes lack permission callbacks, and there are no nonce checks, making them potentially vulnerable to unauthorized access and manipulation.
The taint analysis, while not revealing critical or high severity issues, indicates that all analyzed flows involve unsanitized paths. This, combined with the unprotected REST API endpoints and lack of capability checks, suggests a potential for injection-type vulnerabilities or unauthorized data access if malicious input is provided. The presence of file operations and external HTTP requests also warrants careful review to ensure they are implemented securely and do not introduce further risks. Overall, while the plugin avoids common pitfalls like unpatched CVEs or raw SQL, its exposed entry points and unsanitized paths require immediate attention to mitigate potential security risks.
Key Concerns
- REST API routes without permission callbacks
- Total entry points unprotected
- Flows with unsanitized paths
- No nonce checks
- No capability checks
- File operations present
- External HTTP requests present
SnapScan Payment Gateway Security Vulnerabilities
SnapScan Payment Gateway Code Analysis
Output Escaping
Data Flow Analysis
SnapScan Payment Gateway Attack Surface
REST API Routes 3
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
SnapScan Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
SnapScan Payment Gateway Alternatives
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Bangladeshi Payment Gateways – Make Payment Using QR Code
bangladeshi-payment-gateways
Bangladeshi Payment Gateways for WooCommerce.
Payment Methods by Product & Country for WooCommerce
payment-gateways-per-product-categories-for-woocommerce
Use products and countries conditional rules to show/hide gateways, increase profit margins & optimize operations for your products by restricting …
SnapScan Payment Gateway Developer Profile
1 plugin · 700 total installs
How We Detect SnapScan Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/snapscan-online-payments/EcentricGateway/card-woocommerce-gateway.php/wp-content/plugins/snapscan-online-payments/common/admin-notice.php/wp-content/plugins/snapscan-online-payments/common/snap-logger.php/wp-content/plugins/snapscan-online-payments/SnapScan/woocommerce-snapscan.phpsnapscan-online-payments/EcentricGateway/card-woocommerce-gateway.php?ver=snapscan-online-payments/common/admin-notice.php?ver=snapscan-online-payments/common/snap-logger.php?ver=snapscan-online-payments/SnapScan/woocommerce-snapscan.php?ver=HTML / DOM Fingerprints
snapscan-card-gateway<!-- SnapScan Card Payment Error:data-snap-merchant-iddata-snap-api-keywindow.SnapScanSnapScanPayment/wp-json/snapscan/v1/payments[snapscan_payment_button]