TurtleNetwork Gateway for Woocommerce Security & Risk Analysis

wordpress.org/plugins/tn-gateway-for-woocommerce

Show prices in TN or any other token on TurtleNetwork and accept payments with that token your woocommerce webshop

0 active installs v0.0.1 PHP + WP + Updated Apr 27, 2019
billinginvoicingpaymenttnwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TurtleNetwork Gateway for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

TurtleNetwork Gateway for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "tn-gateway-for-woocommerce" v0.0.1 exhibits a concerning security posture due to a single unprotected AJAX entry point. While the code demonstrates good practices in using prepared statements for SQL queries and avoids dangerous functions or file operations, the lack of authentication checks on its AJAX handler presents a significant risk. This unprotected endpoint could potentially be exploited by an attacker to perform unauthorized actions within the WordPress environment.

The static analysis reveals a limited attack surface, with all entry points consolidated into a single AJAX handler. However, the absence of nonces, capability checks, or any form of authorization for this specific handler is a critical oversight. The taint analysis found no issues, and the vulnerability history is clean, which suggests a lack of past exploitable flaws. Nevertheless, the presence of an unprotected entry point in the current version, regardless of historical data, demands immediate attention.

In conclusion, while the plugin shows strengths in its database interaction and avoidance of common risky coding patterns, the single, unprotected AJAX endpoint is a major weakness. This vulnerability could be exploited without requiring user authentication, making it a prime target for malicious actors. It is strongly recommended that this unprotected AJAX handler be secured with appropriate authentication and authorization mechanisms before the plugin is deployed in a production environment.

Key Concerns

  • Unprotected AJAX handler
  • Lack of nonce checks
  • Lack of capability checks
  • Low output escaping percentage
Vulnerabilities
None known

TurtleNetwork Gateway for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TurtleNetwork Gateway for Woocommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

TurtleNetwork Gateway for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

46% escaped28 total outputs
Attack Surface
1 unprotected

TurtleNetwork Gateway for Woocommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_check_tn_paymentincludes/class-tn-ajax.php:30
WordPress Hooks 11
actionwp_enqueue_scriptsincludes/class-tn-gateway.php:60
actionplugins_loadedtn-gateway-for-woocommerce.php:54
filterwoocommerce_payment_gatewaystn-gateway-for-woocommerce.php:94
filterwoocommerce_currenciestn-gateway-for-woocommerce.php:95
filterwoocommerce_currency_symboltn-gateway-for-woocommerce.php:96
filterwoocommerce_get_price_htmltn-gateway-for-woocommerce.php:98
filterwoocommerce_cart_item_pricetn-gateway-for-woocommerce.php:99
filterwoocommerce_cart_item_subtotaltn-gateway-for-woocommerce.php:100
filterwoocommerce_cart_subtotaltn-gateway-for-woocommerce.php:101
filterwoocommerce_cart_totals_order_total_htmltn-gateway-for-woocommerce.php:102
actionplugins_loadedtn-gateway-for-woocommerce.php:183
Maintenance & Trust

TurtleNetwork Gateway for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedApr 27, 2019
PHP min version
Downloads960

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TurtleNetwork Gateway for Woocommerce Developer Profile

Роман Иноземцев

3 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TurtleNetwork Gateway for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tn-gateway-for-woocommerce/assets/js/main.js/wp-content/plugins/tn-gateway-for-woocommerce/assets/css/style.css
Script Paths
/wp-content/plugins/tn-gateway-for-woocommerce/assets/js/main.js
Version Parameters
tn-gateway-for-woocommerce/assets/js/main.js?ver=tn-gateway-for-woocommerce/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
tn-gateway-for-woocommerce
Data Attributes
data-tn-asset-iddata-tn-address
JS Globals
window.tn_gateway_params
FAQ

Frequently Asked Questions about TurtleNetwork Gateway for Woocommerce