Tochka Bank: Internet-acquiring Security & Risk Analysis

wordpress.org/plugins/tochka-bank-internet-acquiring

Payment gateway for Tochka Bank in WooCommerce. Accept payments via bank cards and Faster Payments System (SBP).

40 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Jan 10, 2026
credit-cardpayment-gatewaypaymentstochkawoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Tochka Bank: Internet-acquiring Safe to Use in 2026?

Generally Safe

Score 100/100

Tochka Bank: Internet-acquiring has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The Tochka Bank Internet Acquiring plugin v1.0.0 exhibits a strong initial security posture based on static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Importantly, all SQL queries use prepared statements, and the presence of a nonce check, albeit only one, is a positive sign. The limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events further contributes to its security.

However, the analysis is hindered by zero taint flow analysis, meaning potential data manipulation vulnerabilities that are not immediately apparent from function calls might be missed. The most significant concern arises from the lack of capability checks for any potential entry points, and the incomplete output escaping (81%) suggests a residual risk of Cross-Site Scripting (XSS) vulnerabilities. Given that there is no recorded vulnerability history, it's difficult to assess past security practices or recurring issues, but the current version appears to have learned from potential past mistakes or is developed with good security awareness.

In conclusion, while the plugin demonstrates good security practices in several key areas and has a clean vulnerability history, the lack of comprehensive taint analysis and the presence of partially unescaped output warrant attention. The absence of capability checks on any potential entry points is also a notable weakness that could be exploited if an attack surface were to be introduced in future versions. Overall, the plugin appears to be relatively secure for its current version and feature set, but ongoing vigilance and further analysis are recommended.

Key Concerns

  • Output escaping is not 100%
  • No capability checks found
  • No taint flow analysis performed
Vulnerabilities
None known

Tochka Bank: Internet-acquiring Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tochka Bank: Internet-acquiring Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped16 total outputs
Attack Surface

Tochka Bank: Internet-acquiring Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\Bootstrap.php:29
actionbefore_woocommerce_initincludes\HooksManager.php:29
filterwoocommerce_payment_gatewaysincludes\HooksManager.php:30
actionwoocommerce_blocks_loadedincludes\HooksManager.php:31
actioninitincludes\HooksManager.php:34
actiontemplate_redirectincludes\HooksManager.php:35
actionadmin_enqueue_scriptsincludes\HooksManager.php:39
actionwp_enqueue_scriptsincludes\HooksManager.php:45
actionwoocommerce_blocks_payment_method_type_registrationincludes\HooksManager.php:104
Maintenance & Trust

Tochka Bank: Internet-acquiring Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version7.4
Downloads189

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Tochka Bank: Internet-acquiring Developer Profile

Точка

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tochka Bank: Internet-acquiring

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tochka-bank-internet-acquiring/assets/css/admin.css/wp-content/plugins/tochka-bank-internet-acquiring/assets/css/frontend.css/wp-content/plugins/tochka-bank-internet-acquiring/assets/js/frontend.js
Version Parameters
tochka-bank-internet-acquiring/assets/css/admin.css?ver=tochka-bank-internet-acquiring/assets/css/frontend.css?ver=tochka-bank-internet-acquiring/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
tochka-settings-section-title
HTML Comments
/* * Стиль для заголовка-разделителя (h3). *//* * Стиль для таблицы настроек, которая идет СРАЗУ ПОСЛЕ нашего заголовка. */
Data Attributes
data-section="checkout"data-gateway="tochka_bank_internet_acquiring"data-order-iddata-order-key
JS Globals
tochka_payment_data
REST Endpoints
/wp-json/tochka/v1/payment-statuses
FAQ

Frequently Asked Questions about Tochka Bank: Internet-acquiring