
SumUp Payment Gateway For WooCommerce Security & Risk Analysis
wordpress.org/plugins/sumup-payment-gateway-for-woocommerceThe SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Is SumUp Payment Gateway For WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100SumUp Payment Gateway For WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "sumup-payment-gateway-for-woocommerce" plugin, version 2.8.2, exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and a reasonable proportion of output escaping. It also has a moderate number of capability checks, suggesting some effort towards access control.
However, several areas raise concerns. The plugin has a notable attack surface with two unprotected entry points: one AJAX handler and two REST API routes lacking permission callbacks. While no critical or high severity taint flows were identified, one flow with an unsanitized path exists. The plugin also has a history of vulnerabilities, specifically a medium severity one, indicating potential recurring weaknesses. The presence of only one nonce check for its attack surface is also a point of concern, especially with unprotected AJAX handlers.
Overall, while the plugin avoids critical code-level vulnerabilities in this version and has a good record with SQL, the unprotected entry points and the historical vulnerability pattern warrant attention. The presence of an unsanitized path flow, though not classified as critical, is a direct code-level risk that should be addressed. Users should be aware of these potential weaknesses and monitor for future updates that address these specific concerns.
Key Concerns
- Unprotected REST API routes
- Unprotected AJAX handler
- Flow with unsanitized paths
- Historical medium vulnerability
- Limited nonce checks on attack surface
SumUp Payment Gateway For WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SumUp Payment Gateway For WooCommerce <= 2.7.9 - Missing Authorization
SumUp Payment Gateway For WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
SumUp Payment Gateway For WooCommerce Attack Surface
AJAX Handlers 1
REST API Routes 3
WordPress Hooks 27
Maintenance & Trust
SumUp Payment Gateway For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SumUp Payment Gateway For WooCommerce Alternatives
MONEI Payments for WooCommerce
monei
Accept Card, Apple Pay, Google Pay, Bizum, PayPal and many more payment methods in your WooCommerce store using MONEI payment gateway.
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Ecart Pay
ecart-pay
Ecart Pay allows online merchants to quickly and securely accept payments through WooCommerce. With multiple payment options, this plugin is easy to s …
kevin. Payment Gateway for WooCommerce
e-commerce-payment-gateway-kevin
kevin. Payment Gateway plugin for WooCommerce. Let your customers make fast, simple and secure payments directly from their bank accounts across Europ …
Nimbbl
nimbbl-for-woocommerce
Welcome to the official Nimbbl WooCommerce plugin, support auto-fill address. Get higher conversions with multiple payment gateways, COD, UPI, BNPL an …
SumUp Payment Gateway For WooCommerce Developer Profile
1 plugin · 10K total installs
How We Detect SumUp Payment Gateway For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/css/settings.css/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/js/settings.min.js/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/js/sumup-checkout.min.js/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/js/sumup-onboarding.min.js/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/js/settings.min.js/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/js/sumup-checkout.min.js/wp-content/plugins/sumup-payment-gateway-for-woocommerce/assets/js/sumup-onboarding.min.jssumup-payment-gateway-for-woocommerce/assets/css/settings.css?ver=sumup-payment-gateway-for-woocommerce/assets/js/settings.min.js?ver=sumup-payment-gateway-for-woocommerce/assets/js/sumup-checkout.min.js?ver=sumup-payment-gateway-for-woocommerce/assets/js/sumup-onboarding.min.js?ver=HTML / DOM Fingerprints
sumup-payment-gateway-for-woocommercedata-sumup-api-keydata-sumup-gateway-urldata-sumup-gateway-currencydata-sumup-checkout-urlsumup_checkoutsumup_connectsumup_onboarding_init/wp-json/sumup-payment-gateway-for-woocommerce/v1/connect/wp-json/sumup-payment-gateway-for-woocommerce/v1/disconnect