Sparkle 2CO Digital Payment Lite Security & Risk Analysis

wordpress.org/plugins/sparkle-2co-digital-payment-lite

Use 2checkout Payment Gateway for your potential customers and take your eCommerce platform to next level.

0 active installs v1.0.3 PHP 5.4+ WP 4.1+ Updated Apr 2, 2023
2checkout2checkout-payment2co2co-paymentpayment
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sparkle 2CO Digital Payment Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Sparkle 2CO Digital Payment Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "sparkle-2co-digital-payment-lite" v1.0.3 demonstrates a generally good security posture based on the provided static analysis. The absence of direct SQL queries, the high percentage of properly escaped output, and the lack of dangerous functions are positive indicators. The plugin also does not appear to have a history of known vulnerabilities, suggesting a stable and well-maintained codebase. However, there are some areas for concern. The presence of unsanitized paths in all analyzed taint flows, even without a critical or high severity classification, is a red flag that warrants further investigation. Additionally, the complete lack of nonce and capability checks on any entry points is a significant weakness. While the attack surface is currently reported as zero, this could be misleading if any of the external HTTP requests, or the unsanitized paths identified in the taint analysis, were to be leveraged as an indirect attack vector. The plugin's strengths lie in its clean code regarding SQL and output escaping, but the lack of input validation and authorization checks creates potential risks, especially if new entry points are added or existing ones are discovered.

Key Concerns

  • Unsanitized paths in taint flows
  • No nonce checks on entry points
  • No capability checks on entry points
  • External HTTP requests not detailed
Vulnerabilities
None known

Sparkle 2CO Digital Payment Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sparkle 2CO Digital Payment Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
136 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

99% escaped138 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
check_signature (includes\class_sparkle_2checkout_dp_api.php:22)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sparkle 2CO Digital Payment Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionedd_s2coedd_payment_cc_formincludes\edd_plugin_init.php:12
filtersparkle_edd_2checkout_labelincludes\edd_plugin_init.php:14
filteredd_payment_gatewaysincludes\edd_plugin_init.php:15
filteredd_accepted_payment_iconsincludes\edd_plugin_init.php:16
filteredd_settings_sections_gatewaysincludes\edd_plugin_init.php:17
filteredd_settings_gatewaysincludes\edd_plugin_init.php:18
actionedd_gateway_s2coedd_paymentincludes\edd_plugin_init.php:19
actionwpincludes\edd_plugin_init.php:21
actioninitincludes\edd_plugin_init.php:24
actioninitincludes\edd_plugin_init.php:27
filterwoocommerce_payment_gatewaysincludes\woo_plugin_init.php:12
actionplugins_loadedincludes\woo_plugin_init.php:13
actionwpincludes\woo_plugin_init.php:15
actionwoocommerce_review_order_before_submitincludes\woo_plugin_init.php:17
actioninitincludes\woo_plugin_init.php:20
actioninitincludes\woo_plugin_init.php:23
actionadmin_noticessparkle-2co-digital-payment-lite.php:67
actionplugins_loadedsparkle-2co-digital-payment-lite.php:129
Maintenance & Trust

Sparkle 2CO Digital Payment Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 2, 2023
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sparkle 2CO Digital Payment Lite Developer Profile

Sparkle WP

36 plugins · 14K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
193 days
View full developer profile
Detection Fingerprints

How We Detect Sparkle 2CO Digital Payment Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sparkle-2co-digital-payment-lite/assets/images/icon1.png

HTML / DOM Fingerprints

JS Globals
Sparkle_2CO_Digital_Payment_Lite
FAQ

Frequently Asked Questions about Sparkle 2CO Digital Payment Lite