Transactium WooCommerce AddOn Security & Risk Analysis

wordpress.org/plugins/transactium-woocommerce-addon

Spark the most flexible eCommerce solution for WordPress, WooCommerce, and process payments via Transactium EZPay!

20 active installs v1.18 PHP + WP 3.9+ Updated Feb 18, 2025
ecommercepaymentpaymentstransactiumwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Transactium WooCommerce AddOn Safe to Use in 2026?

Generally Safe

Score 92/100

Transactium WooCommerce AddOn has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "transactium-woocommerce-addon" v1.18 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs in its history is a significant positive. Furthermore, the plugin demonstrates strong coding practices by utilizing prepared statements for all SQL queries and performing a high percentage of output escaping. The limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation.

However, there are a few areas of concern that warrant attention. The presence of three identified taint flows with unsanitized paths, even without reported critical or high severities, suggests potential risks. While the direct impact isn't quantified, unsanitized paths can lead to various vulnerabilities if input is not properly handled. Additionally, the complete lack of nonce checks and capability checks is a notable weakness. This means that actions, even if they don't directly interact with the database or external systems in a way that triggered other static analysis flags, could be susceptible to Cross-Site Request Forgery (CSRF) attacks or unauthorized access by users who shouldn't have permission.

In conclusion, the plugin has a solid foundation with its secure SQL handling and good output escaping. The zero known vulnerabilities are reassuring. However, the identified unsanitized paths and the complete absence of nonce and capability checks represent genuine security risks that should be addressed to achieve a more robust security posture. Prioritizing the investigation and sanitization of the identified taint flows and implementing appropriate authorization checks are crucial next steps.

Key Concerns

  • Taint flows with unsanitized paths found
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Transactium WooCommerce AddOn Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Transactium WooCommerce AddOn Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

77% escaped35 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
transactium_woocommerce_addon_init (transactium-woocommerce-addon.php:17)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Transactium WooCommerce AddOn Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedtransactium-woocommerce-addon.php:16
actionadmin_noticestransactium-woocommerce-addon.php:132
actionwoocommerce_credit_card_form_endtransactium-woocommerce-addon.php:147
actionwoocommerce_api_wc_gateway_transactium_woocommerce_addontransactium-woocommerce-addon.php:153
actionwoocommerce_scheduled_subscription_payment_transactium_woocommerce_addontransactium-woocommerce-addon.php:159
actionwoocommerce_order_details_after_order_tabletransactium-woocommerce-addon.php:167
filterwoocommerce_email_customer_details_fieldstransactium-woocommerce-addon.php:210
filterwoocommerce_payment_gatewaystransactium-woocommerce-addon.php:1948
Maintenance & Trust

Transactium WooCommerce AddOn Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 18, 2025
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Transactium WooCommerce AddOn Developer Profile

transactiumdev

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Transactium WooCommerce AddOn

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Transactium WooCommerce AddOn