StellarPay – Stripe Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/stellarpay

StellarPay is a free Stripe WordPress plugin that makes online payments simple for WooCommerce stores.

200 active installs v1.9.1 PHP 7.4+ WP 6.2+ Updated Aug 19, 2025
gatewaypaymentstripestripe-payment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is StellarPay – Stripe Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

StellarPay – Stripe Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The stellarpay plugin v1.9.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The lack of identified CVEs, combined with a history of no recorded vulnerabilities, suggests a well-maintained and secure codebase. The static analysis reveals no critical or high severity taint flows, no dangerous functions, and no file operations, which are significant strengths. Furthermore, the plugin demonstrates good security practices with a high percentage of SQL queries using prepared statements and a substantial portion of outputs being properly escaped. The presence of numerous nonce and capability checks further indicates an awareness of common WordPress security vulnerabilities.

While the plugin's attack surface appears to be zero, meaning no direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events were detected, this could be an incomplete picture or indicate a very specialized, potentially backend-only functionality. The bundling of the Stripe PHP library is noted, and while not flagged as an issue here, keeping bundled libraries updated is crucial for long-term security. Overall, the plugin appears to be in a very good security state, with no immediate exploitable vulnerabilities apparent from the provided data. The strengths heavily outweigh any potential minor concerns.

Key Concerns

  • Bundled Stripe PHP library
Vulnerabilities
None known

StellarPay – Stripe Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

StellarPay – Stripe Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
11 prepared
Unescaped Output
50
255 escaped
Nonce Checks
9
Capability Checks
19
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Stripe PHP

SQL Query Safety

92% prepared12 total queries

Output Escaping

84% escaped305 total outputs
Attack Surface

StellarPay – Stripe Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionwoocommerce_ajax_save_product_variationssrc\Integrations\WooCommerce\Controllers\SaveVariableProductSettings.php:60
actionbefore_woocommerce_initsrc\Integrations\WooCommerce\ServiceProvider.php:141
filterwoocommerce_payment_gatewayssrc\Integrations\WooCommerce\ServiceProvider.php:147
actionwoocommerce_blocks_loadedsrc\Integrations\WooCommerce\ServiceProvider.php:157
actionwoocommerce_blocks_payment_method_type_registrationsrc\Integrations\WooCommerce\ServiceProvider.php:158
filterwoocommerce_email_classessrc\Integrations\WooCommerce\ServiceProvider.php:315
filterwc_stellarpay_stripe_generate_payment_intent_datasrc\Integrations\WooCommerce\Stripe\Controllers\PrePaymentProcessLegacyCheckout.php:80
filterwc_stellarpay_stripe_generate_payment_intent_datasrc\Integrations\WooCommerce\Stripe\Controllers\PrePaymentProcessor.php:81
actionwpsrc\Integrations\WooCommerce\Stripe\Controllers\ReturnResultInJsonFormatForOrderPayPayment.php:92
actionwoocommerce_blocks_enqueue_checkout_block_scripts_beforesrc\Integrations\WooCommerce\Stripe\PaymentGatewayCheckoutBlockSupport.php:83
filterwoocommerce_get_customer_payment_tokenssrc\Integrations\WooCommerce\Stripe\PaymentGatewayCheckoutBlockSupport.php:86
actionwoocommerce_blocks_enqueue_checkout_block_scripts_endsrc\Integrations\WooCommerce\Stripe\PaymentGatewayCheckoutBlockSupport.php:92
filterwoocommerce_order_data_store_cpt_get_orders_querysrc\Integrations\WooCommerce\Stripe\Repositories\CustomerRepository.php:95
actionadmin_initsrc\PaymentGateways\ServiceProvider.php:90
actionadmin_initsrc\PaymentGateways\ServiceProvider.php:108
actionadmin_enqueue_scriptssrc\PluginSetup\Actions\RegisterDeactivationModel.php:52
actionadmin_footersrc\PluginSetup\Actions\RegisterDeactivationModel.php:54
Maintenance & Trust

StellarPay – Stripe Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 19, 2025
PHP min version7.4
Downloads14K

Community Trust

Rating86/100
Number of ratings4
Active installs200
Developer Profile

StellarPay – Stripe Payment Gateway for WooCommerce Developer Profile

StellarWP

26 plugins · 3.1M total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
462 days
View full developer profile
Detection Fingerprints

How We Detect StellarPay – Stripe Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stellarpay/assets/css/admin.css/wp-content/plugins/stellarpay/assets/css/checkout.css/wp-content/plugins/stellarpay/assets/css/frontend.css/wp-content/plugins/stellarpay/assets/js/admin.js/wp-content/plugins/stellarpay/assets/js/checkout.js/wp-content/plugins/stellarpay/assets/js/frontend.js
Script Paths
/wp-content/plugins/stellarpay/assets/js/admin.js/wp-content/plugins/stellarpay/assets/js/checkout.js/wp-content/plugins/stellarpay/assets/js/frontend.js
Version Parameters
stellarpay/assets/css/admin.css?ver=stellarpay/assets/css/checkout.css?ver=stellarpay/assets/css/frontend.css?ver=stellarpay/assets/js/admin.js?ver=stellarpay/assets/js/checkout.js?ver=stellarpay/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
stellarpay-dashboard-containerstellarpay-section-headerstellarpay-payment-settingsstellarpay-account-detailsstellarpay-modal-backdropstellarpay-modal-contentstellarpay-settings-fieldstellarpay-connect-stripe-button
HTML Comments
<!-- Start StellarPay --><!-- StellarPay Autoloader. --><!-- Boot the plugin. --><!-- Admin Menu -->+42 more
Data Attributes
data-stellarpay-modal-targetdata-stellarpay-field-iddata-stellarpay-gateway-id
JS Globals
window.StellarPayAdminwindow.StellarPayCheckoutwindow.StellarPayFrontendStellarPay
REST Endpoints
/wp-json/stellarpay/v1/settings/wp-json/stellarpay/v1/account/connect/wp-json/stellarpay/v1/account/disconnect/wp-json/stellarpay/v1/dashboard/stats/wp-json/stellarpay/v1/payment/capture/wp-json/stellarpay/v1/payment/refund
FAQ

Frequently Asked Questions about StellarPay – Stripe Payment Gateway for WooCommerce