
Trust Payments Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/trust-payments-hosted-payment-pages-integrationThis plugin offers a simple and easy to implement method for merchants to add e-payment capabilities to their WooCommerce online commerce setup.
Is Trust Payments Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100Trust Payments Gateway for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "trust-payments-hosted-payment-pages-integration" plugin v2.1.1 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, with all 8 utilizing prepared statements, and a very high percentage (97%) of output escaping, indicating a strong defense against common injection vulnerabilities. The absence of file operations and bundled libraries also reduces potential attack vectors.
However, there are notable areas of concern. The plugin presents a significant attack surface with 25 entry points, 4 of which lack authentication checks. This is a critical oversight as it allows unauthenticated users to trigger potentially sensitive actions. While taint analysis shows no critical or high severity flows, 2 flows with unsanitized paths warrant attention, as they could be exploited under certain conditions. Furthermore, the plugin has a history of one high severity CVE, a SQL Injection vulnerability, which, although currently patched, suggests a historical susceptibility to such attacks. The lack of capability checks on AJAX handlers is also a significant weakness that could be exploited.
In conclusion, while the plugin has implemented robust defenses against SQL injection and output escaping, the substantial number of unprotected AJAX handlers and the historical high-severity vulnerability are significant weaknesses. The presence of unsanitized paths in taint analysis, though not currently critical, should also be addressed. Improvements in authentication and authorization for entry points are crucial to enhance the overall security.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Historical high severity CVE
- Lack of capability checks
Trust Payments Gateway for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Trust Payments Gateway for WooCommerce <= 1.1.4 - Unauthenticated SQL Injection
Trust Payments Gateway for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Trust Payments Gateway for WooCommerce Attack Surface
AJAX Handlers 24
Shortcodes 1
WordPress Hooks 63
Maintenance & Trust
Trust Payments Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Trust Payments Gateway for WooCommerce Alternatives
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Payment Plugins for Stripe WooCommerce
woo-stripe-payment
Accept Credit Cards, Google Pay, ApplePay, Afterpay, Affirm, ACH, Klarna, iDEAL and more all in one plugin for free!
Payment Gateway of Stripe for WooCommerce
payment-gateway-stripe-and-woocommerce-integration
Integrate Stripe Payment Gateway in WooCommerce and accept cards, Google Pay, Apple Pay, Klarna, Alipay, and more with seamless, secure checkout.
Sola Payment Gateway for WooCommerce
woo-cardknox-gateway
Accept payments with the Sola gateway.
Mobipaid
mobipaid
Payments over multiple channels
Trust Payments Gateway for WooCommerce Developer Profile
2 plugins · 700 total installs
How We Detect Trust Payments Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trust-payments-hosted-payment-pages-integration/assets/js/tp-admin.js/wp-content/plugins/trust-payments-hosted-payment-pages-integration/assets/css/tp-admin.csshttps://securetrading.com/v2/api/js/securetrading.jstrust-payments-hosted-payment-pages-integration/assets/js/tp-admin.js?ver=trust-payments-hosted-payment-pages-integration/assets/css/tp-admin.css?ver=HTML / DOM Fingerprints
tp_admin_headingtp_admin_tab_linkstp_admin_submit_buttontp_admin_field_labeltp_admin_field_inputtp_admin_error_messagetp_admin_success_messagetp_admin_settings_form+2 more<!-- Trust Payments Gateway Settings --><!-- End Trust Payments Gateway Settings --><!-- Trust Payments Hosted Payment Pages Integration --><!-- End Trust Payments Hosted Payment Pages Integration -->+2 moredata-tp-payment-methoddata-tp-order-iddata-tp-transaction-iddata-tp-redirect-urldata-tp-merchant-iddata-tp-site-reference+1 moretp_admin/wp-json/trust-payments/v1/process-payment/wp-json/trust-payments/v1/webhook[trust_payments_payment_form][trust_payments_order_status][trust_payments_subscription_form]