
Total processing card payments for WooCommerce Security & Risk Analysis
wordpress.org/plugins/totalprocessing-card-paymentsAccept Credit Cards and Debit Cards on your WooCommerce store.
Is Total processing card payments for WooCommerce Safe to Use in 2026?
Generally Safe
Score 96/100Total processing card payments for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "totalprocessing-card-payments" plugin v7.3 presents a mixed security posture with some positive aspects but notable areas of concern. The presence of 8 unprotected AJAX handlers significantly expands the attack surface, potentially allowing unauthenticated users to trigger sensitive actions. While the plugin largely utilizes prepared statements for SQL queries (65%), the remaining 35% may still be susceptible to SQL injection if not handled carefully. The high percentage of unsanitized paths in taint analysis (16 out of 20 flows) is a major red flag, indicating a strong likelihood of path traversal vulnerabilities, especially given the plugin's history of such issues. Furthermore, only 54% of output is properly escaped, increasing the risk of cross-site scripting (XSS) attacks, which aligns with the plugin's historical vulnerability types.
Despite these concerns, the plugin does not appear to bundle outdated libraries and has no currently unpatched CVEs. The existence of 3 CVEs in its history, particularly a high-severity one related to path traversal and medium-severity ones for XSS, suggests a recurring pattern of input sanitization and output escaping deficiencies. While the current version may have fixed past vulnerabilities, the high number of unprotected entry points and unsanitized taint flows indicate that the underlying architectural weaknesses may persist, making it a prime target for attackers. Therefore, while there are some positive indicators, the significant number of unprotected entry points and the concerning taint analysis results warrant cautious evaluation.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low output escaping percentage
- Vulnerability history (1 High, 2 Medium)
- SQL queries not using prepared statements
Total processing card payments for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Nomupay Payment Processing Gateway <= 7.1.7 - Authenticated (Shop Manager+) Arbitrary File Download
Nomupay Payment Processing Gateway <= 7.1.6 - Reflected Cross-Site Scripting
Nomupay Payment Processing Gateway <= 7.1.5 - Authenticated (Subscriber+) Arbitrary File Download
Total processing card payments for WooCommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Total processing card payments for WooCommerce Attack Surface
AJAX Handlers 12
WordPress Hooks 71
Scheduled Events 3
Maintenance & Trust
Total processing card payments for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Total processing card payments for WooCommerce Alternatives
Checkout.com Payment Gateway
checkout-com-unified-payments-api
Checkout.com helps your business offer more payment methods and currencies to more customers. We provide best-in-class payment processing for credit c …
Nomod for WooCommerce
nomod-for-woocommerce
Accept major cards, Apple Pay, Google Pay, Mada, Tabby & Tamara on your store. Get same-day payouts, no monthly fees & amazing support!
ECOMMPAY Payments
ecommpay-payments
Accept bank transfers, cards, local payment methods and cryptocurrencies. Boost conversion with a customisable checkout form.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Total processing card payments for WooCommerce Developer Profile
1 plugin · 100 total installs
How We Detect Total processing card payments for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/admin/css/totalprocessing-card-payments-and-gateway-woocommerce-admin.css/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/admin/js/totalprocessing-card-payments-and-gateway-woocommerce-admin.js/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/assets/css/totalprocessing-card-payments-and-gateway-woocommerce.css/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/assets/js/totalprocessing-card-payments-and-gateway-woocommerce.js/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/includes/logger/admin/css/tp-logs-settings.css/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/includes/logger/admin/js/tp-logs-settings.js/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/admin/js/totalprocessing-card-payments-and-gateway-woocommerce-admin.js/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/assets/js/totalprocessing-card-payments-and-gateway-woocommerce.js/wp-content/plugins/totalprocessing-card-payments-and-gateway-woocommerce/includes/logger/admin/js/tp-logs-settings.jstotalprocessing-card-payments-and-gateway-woocommerce/admin/css/totalprocessing-card-payments-and-gateway-woocommerce-admin.css?ver=totalprocessing-card-payments-and-gateway-woocommerce/admin/js/totalprocessing-card-payments-and-gateway-woocommerce-admin.js?ver=totalprocessing-card-payments-and-gateway-woocommerce/assets/css/totalprocessing-card-payments-and-gateway-woocommerce.css?ver=totalprocessing-card-payments-and-gateway-woocommerce/assets/js/totalprocessing-card-payments-and-gateway-woocommerce.js?ver=totalprocessing-card-payments-and-gateway-woocommerce/includes/logger/admin/css/tp-logs-settings.css?ver=totalprocessing-card-payments-and-gateway-woocommerce/includes/logger/admin/js/tp-logs-settings.js?ver=HTML / DOM Fingerprints
tp-gateway-logger-settings-wrap<!-- currently plugin version --><!-- check for version updates --><!-- plugin activation hook --><!-- plugin deactivation hook -->+7 moredata-tp-gateway-option-nametotalprocessing_gateway_settingstotalprocessing_gateway_log_data/wp-json/totalprocessing-card-payments-and-gateway-woocommerce/v1/settings/wp-json/totalprocessing-card-payments-and-gateway-woocommerce/v1/logs/wp-json/totalprocessing-card-payments-and-gateway-woocommerce/v1/log/delete