Straumur Payments For WooCommerce Security & Risk Analysis

wordpress.org/plugins/straumur-payments-for-woocommerce

Integrate Straumur’s Hosted Checkout into your WooCommerce store. Supports subscriptions, customizable payment pages, redirects, and detailed order no …

100 active installs v2.0.3 PHP 7.4+ WP 5.2+ Updated Jul 29, 2025
paymentsstraumursubscriptionswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Straumur Payments For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Straumur Payments For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The 'straumur-payments-for-woocommerce' v2.0.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or unsanitized taint flows is a significant positive indicator. Furthermore, the plugin demonstrates excellent adherence to WordPress security best practices, with nearly all output properly escaped, a single external HTTP request for potential integrations, and robust use of nonce and capability checks for its entry points. The attack surface is minimal and appears to be adequately protected.

The plugin's vulnerability history is also exceptionally clean, with no recorded CVEs. This lack of past vulnerabilities, combined with the current clean static analysis, suggests a development team that prioritizes security or has been fortunate to avoid significant discovered flaws. However, it's important to note that the analysis of taint flows was limited (0 flows analyzed), which could mean that potential issues exist but were not detectable by the static analysis tool's current configuration or capabilities. While the current evidence points to a secure plugin, continuous monitoring and security audits are always recommended, especially for plugins handling payment processing.

In conclusion, 'straumur-payments-for-woocommerce' v2.0.3 demonstrates a very good security profile. Its strengths lie in its well-protected entry points, proper use of SQL prepared statements, and high percentage of escaped output. The absence of known vulnerabilities is a strong positive. The only minor point of caution would be the limited scope of the taint analysis, which is a technical limitation of the analysis rather than a direct finding of a flaw.

Vulnerabilities
None known

Straumur Payments For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Straumur Payments For WooCommerce Release Timeline

v2.0.3Current
v2.0.2
v2.0.1
v2.0.0
v1.1.3
v1.1.2
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Straumur Payments For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
55 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped56 total outputs
Attack Surface

Straumur Payments For WooCommerce Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

GET/wp-json/straumur/v1/payment-callbackincludes\class-wc-straumur-webhook-handler.php:76
WordPress Hooks 19
actionwoocommerce_blocks_payment_method_type_registrationincludes\class-wc-straumur-block-support.php:24
actionwoocommerce_scheduled_subscription_payment_straumurincludes\class-wc-straumur-payment-gateway.php:83
actionwoocommerce_subscription_payment_method_updated_to_straumurincludes\class-wc-straumur-payment-gateway.php:84
actionwp_enqueue_scriptsincludes\class-wc-straumur-payment-gateway.php:87
actionrest_api_initincludes\class-wc-straumur-webhook-handler.php:65
actionadmin_noticesstraumur-payments-for-woocommerce.php:163
filterwoocommerce_store_api_get_customer_payment_tokensstraumur-payments-for-woocommerce.php:188
filterwoocommerce_get_customer_payment_tokensstraumur-payments-for-woocommerce.php:194
actionbefore_woocommerce_initstraumur-payments-for-woocommerce.php:202
actionenqueue_block_assetsstraumur-payments-for-woocommerce.php:216
filterwoocommerce_payment_gatewaysstraumur-payments-for-woocommerce.php:219
actionbefore_woocommerce_initstraumur-payments-for-woocommerce.php:222
filterplugin_row_metastraumur-payments-for-woocommerce.php:242
actionwoocommerce_order_status_on-hold_to_cancelledstraumur-payments-for-woocommerce.php:248
actionwoocommerce_order_status_on-hold_to_processingstraumur-payments-for-woocommerce.php:259
actionwoocommerce_order_status_on-hold_to_completedstraumur-payments-for-woocommerce.php:270
actionwoocommerce_order_status_processing_to_refundedstraumur-payments-for-woocommerce.php:281
actionwoocommerce_order_status_completed_to_refundedstraumur-payments-for-woocommerce.php:292
actionplugins_loadedstraumur-payments-for-woocommerce.php:365
Maintenance & Trust

Straumur Payments For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 29, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Straumur Payments For WooCommerce Developer Profile

Straumur Greiðslumiðlun hf.

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Straumur Payments For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/straumur-payments-for-woocommerce/assets/js/straumur-block-payment-method.js
Script Paths
/wp-content/plugins/straumur-payments-for-woocommerce/assets/js/straumur-block-payment-method.js
Version Parameters
straumur-payments-for-woocommerce/assets/js/straumur-block-payment-method.js?ver=

HTML / DOM Fingerprints

CSS Classes
straumur-block-payment-method
JS Globals
Straumur_Block_Payment_Method
FAQ

Frequently Asked Questions about Straumur Payments For WooCommerce