tatrapay+ Payment Gateway Security & Risk Analysis

wordpress.org/plugins/tatrapay-payment-gateway

Latest payment processing solution from Tatrabanka. Accept Pay Later, credit/debit cards and bank accounts.

200 active installs v1.2.11 PHP 7.4+ WP 5.0+ Updated Jan 9, 2026
apple-paycredit-cardgoogle-paypaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is tatrapay+ Payment Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

tatrapay+ Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'tatrapay-payment-gateway' plugin v1.2.11 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The plugin appears to follow good security practices by not exposing a large attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries utilize prepared statements, and a high percentage of output is properly escaped. The absence of file operations and external HTTP requests further contributes to its secure design.

The taint analysis shows no identified flows with unsanitized paths, which is a significant positive indicator. The vulnerability history is also clear, with zero recorded CVEs across all severity levels. This lack of past vulnerabilities suggests diligent maintenance and testing by the developers. The plugin's strengths lie in its minimal attack surface, robust data handling (SQL prepared statements, output escaping), and a clean vulnerability record.

While the current data suggests a highly secure plugin, the complete absence of nonce checks and capability checks across all entry points (even though there are none listed) is a potential theoretical weakness. If any entry points were to be introduced in future versions without these checks, it could pose a risk. However, based on the current version's analysis, there are no immediate, evidence-backed security concerns to highlight. The plugin appears well-developed and maintained.

Vulnerabilities
None known

tatrapay+ Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

tatrapay+ Payment Gateway Release Timeline

v1.3.3
v1.3.2
v1.3.1
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
Code Analysis
Analyzed Apr 16, 2026

tatrapay+ Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
67 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped76 total outputs
Attack Surface

tatrapay+ Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionwoocommerce_blocks_payment_method_type_registrationadmin/class-tatrapayplus-admin.php:120
actionadmin_noticesincludes/class-tatrapayplus-gateway.php:147
filterwoocommerce_generate_image_with_preview_htmlincludes/class-tatrapayplus-gateway.php:148
filterwoocommerce_generate_color_guide_htmlincludes/class-tatrapayplus-gateway.php:155
filterwoocommerce_generate_comfort_pay_file_htmlincludes/class-tatrapayplus-gateway.php:162
actionwoocommerce_api_wc_gateway_tatrapayplusincludes/class-tatrapayplus-gateway.php:169
actionwoocommerce_thankyouincludes/class-tatrapayplus-gateway.php:170
actionwoocommerce_after_cart_totalsincludes/class-tatrapayplus-gateway.php:171
actionenqueue_block_assetsincludes/class-tatrapayplus-gateway.php:172
actionwoocommerce_api_tatrapayplus_cart_totalincludes/class-tatrapayplus-gateway.php:173
actionplugins_loadedincludes/class-tatrapayplus.php:136
actionadmin_enqueue_scriptsincludes/class-tatrapayplus.php:150
actionadmin_enqueue_scriptsincludes/class-tatrapayplus.php:151
actionwoocommerce_payment_gatewaysincludes/class-tatrapayplus.php:152
actionplugins_loadedincludes/class-tatrapayplus.php:153
actiontatrapayplus_check_statusincludes/class-tatrapayplus.php:154
actionwoocommerce_blocks_loadedincludes/class-tatrapayplus.php:155
filterwoocommerce_after_add_to_cart_buttonincludes/class-tatrapayplus.php:156
filterwoocommerce_before_shop_loop_item_titleincludes/class-tatrapayplus.php:157
Maintenance & Trust

tatrapay+ Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 9, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

tatrapay+ Payment Gateway Developer Profile

devtatrabanka

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect tatrapay+ Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tatrapay-payment-gateway/build/paylater.js/wp-content/plugins/tatrapay-payment-gateway/plugin_assets/images/paylater_on_light.svg/wp-content/plugins/tatrapay-payment-gateway/plugin_assets/images/paylater_on_dark.svg/wp-content/plugins/tatrapay-payment-gateway/admin/css/tatrapayplus-admin.css/wp-content/plugins/tatrapay-payment-gateway/admin/js/tatrapayplus-admin.js
Script Paths
https://moja.tatrabanka.sk/ib-mfes/nasplatky-button/1.1.0/main.js
Version Parameters
tatrapayplus-nasplatky-button.js?ver=wc-tatrapayplus-paylater-btn?ver=tatrapayplus-admin?ver=tatrapayplus-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tatrapayplus-paylater
Data Attributes
na-splatky-button
JS Globals
TATRAPAYPLUS_VERSION
FAQ

Frequently Asked Questions about tatrapay+ Payment Gateway