SolPress WooCommerce Payment Gateway Security & Risk Analysis

wordpress.org/plugins/solpress-payment-gateway

Solana Pay for Woocommerce websites. Permissionless, open source, and fast payments. Funded by the Solana Foundation.

30 active installs v2.0.34 PHP 7.0+ WP 4.7+ Updated Sep 9, 2024
crypto-paymentpayment-gatewaysolanasolana-paywoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SolPress WooCommerce Payment Gateway Safe to Use in 2026?

Generally Safe

Score 92/100

SolPress WooCommerce Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The solpress-payment-gateway plugin v2.0.34 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, not utilizing raw SQL queries, and performing a high percentage of output escaping. The absence of known vulnerabilities and CVEs in its history is also a strong indicator of its current security maintenance. Furthermore, it has a clean taint analysis with no observed unsanitized flows, and it doesn't appear to bundle outdated libraries.

However, the plugin has a significant concern regarding its attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This is a critical weakness as it allows any unauthenticated user to potentially interact with these endpoints, leading to unauthorized actions or information disclosure if these handlers are not inherently protected by other WordPress mechanisms. The single external HTTP request could also be a vector if not properly secured, although the static analysis doesn't provide details to assess that risk. The lack of capability checks on these entry points further exacerbates the risk associated with the unprotected AJAX handlers.

In conclusion, while the plugin exhibits good coding hygiene in several areas, the two unprotected AJAX handlers represent a serious security flaw that needs immediate attention. The absence of past vulnerabilities is encouraging, but it doesn't negate the present risk introduced by these exposed endpoints. Addressing these unprotected entry points is paramount to improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers (2)
  • Lack of capability checks on entry points
  • External HTTP request without detail
Vulnerabilities
None known

SolPress WooCommerce Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SolPress WooCommerce Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
14 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

88% escaped16 total outputs
Attack Surface
2 unprotected

SolPress WooCommerce Payment Gateway Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_get_order_totalincludes\class-solpress.php:196
noprivwp_ajax_get_order_totalincludes\class-solpress.php:197
WordPress Hooks 14
actionplugins_loadedincludes\class-solpress.php:149
actionplugins_loadedincludes\class-solpress.php:161
actionwoocommerce_payment_gatewaysincludes\class-solpress.php:162
actionplugin_action_links_solpress/solpress.phpincludes\class-solpress.php:163
actionadmin_enqueue_scriptsincludes\class-solpress.php:178
actionadmin_enqueue_scriptsincludes\class-solpress.php:179
actionadmin_noticesincludes\class-solpress.php:180
actionwp_enqueue_scriptsincludes\class-solpress.php:194
actionwp_enqueue_scriptsincludes\class-solpress.php:195
actionwp_enqueue_scriptsincludes\class-wc-solpress-solana.php:109
actionwoocommerce_review_order_after_paymentincludes\class-wc-solpress-solana.php:112
actionwoocommerce_settings_pricing_optionsincludes\class-wc-solpress-solana.php:124
filterwoocommerce_currenciesincludes\class-wc-solpress-solana.php:144
filterwoocommerce_currency_symbolincludes\class-wc-solpress-solana.php:149
Maintenance & Trust

SolPress WooCommerce Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 9, 2024
PHP min version7.0
Downloads3K

Community Trust

Rating70/100
Number of ratings4
Active installs30
Developer Profile

SolPress WooCommerce Payment Gateway Developer Profile

solpressplugins

2 plugins · 50 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SolPress WooCommerce Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/solpress-payment-gateway/admin/css/solpress-admin.css/wp-content/plugins/solpress-payment-gateway/admin/js/solpress-admin.js
Script Paths
/wp-content/plugins/solpress-payment-gateway/admin/js/solpress-admin.js
Version Parameters
solpress-admin.css?ver=solpress-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
solpress-admin-notice
FAQ

Frequently Asked Questions about SolPress WooCommerce Payment Gateway