
Tochka Bank: Internet-acquiring Security & Risk Analysis
wordpress.org/plugins/tochka-bank-internet-acquiringPayment gateway for Tochka Bank in WooCommerce. Accept payments via bank cards and Faster Payments System (SBP).
Is Tochka Bank: Internet-acquiring Safe to Use in 2026?
Generally Safe
Score 100/100Tochka Bank: Internet-acquiring has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Tochka Bank Internet Acquiring plugin v1.0.0 exhibits a strong initial security posture based on static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Importantly, all SQL queries use prepared statements, and the presence of a nonce check, albeit only one, is a positive sign. The limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events further contributes to its security.
However, the analysis is hindered by zero taint flow analysis, meaning potential data manipulation vulnerabilities that are not immediately apparent from function calls might be missed. The most significant concern arises from the lack of capability checks for any potential entry points, and the incomplete output escaping (81%) suggests a residual risk of Cross-Site Scripting (XSS) vulnerabilities. Given that there is no recorded vulnerability history, it's difficult to assess past security practices or recurring issues, but the current version appears to have learned from potential past mistakes or is developed with good security awareness.
In conclusion, while the plugin demonstrates good security practices in several key areas and has a clean vulnerability history, the lack of comprehensive taint analysis and the presence of partially unescaped output warrant attention. The absence of capability checks on any potential entry points is also a notable weakness that could be exploited if an attack surface were to be introduced in future versions. Overall, the plugin appears to be relatively secure for its current version and feature set, but ongoing vigilance and further analysis are recommended.
Key Concerns
- Output escaping is not 100%
- No capability checks found
- No taint flow analysis performed
Tochka Bank: Internet-acquiring Security Vulnerabilities
Tochka Bank: Internet-acquiring Code Analysis
Output Escaping
Tochka Bank: Internet-acquiring Attack Surface
WordPress Hooks 9
Maintenance & Trust
Tochka Bank: Internet-acquiring Maintenance & Trust
Maintenance Signals
Community Trust
Tochka Bank: Internet-acquiring Alternatives
MONEI Payments for WooCommerce
monei
Accept Card, Apple Pay, Google Pay, Bizum, PayPal and many more payment methods in your WooCommerce store using MONEI payment gateway.
Nomod for WooCommerce
nomod-for-woocommerce
Accept major cards, Apple Pay, Google Pay, Mada, Tabby & Tamara on your store. Get same-day payouts, no monthly fees & amazing support!
Paystation Payment Gateway for woocommerce
paystation-woocommerce-payment-gateway
Take credit card payments on your store via Paystation.
Live eftpos for WooCommerce
live-eftpos-for-woocommerce
The Live eftpos for WooCommerce plugin is the easy way to manage card payments via your online store.
Charge Anywhere Payment Gateway for WooCommerce
charge-anywhere-payment-gateway-for-woocommerce
Charge Anywhere payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Tochka Bank: Internet-acquiring Developer Profile
1 plugin · 40 total installs
How We Detect Tochka Bank: Internet-acquiring
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tochka-bank-internet-acquiring/assets/css/admin.css/wp-content/plugins/tochka-bank-internet-acquiring/assets/css/frontend.css/wp-content/plugins/tochka-bank-internet-acquiring/assets/js/frontend.jstochka-bank-internet-acquiring/assets/css/admin.css?ver=tochka-bank-internet-acquiring/assets/css/frontend.css?ver=tochka-bank-internet-acquiring/assets/js/frontend.js?ver=HTML / DOM Fingerprints
tochka-settings-section-title/*
* Стиль для заголовка-разделителя (h3).
*//*
* Стиль для таблицы настроек, которая идет СРАЗУ ПОСЛЕ нашего заголовка.
*/data-section="checkout"data-gateway="tochka_bank_internet_acquiring"data-order-iddata-order-keytochka_payment_data/wp-json/tochka/v1/payment-statuses