
TrustistEcommerce Security & Risk Analysis
wordpress.org/plugins/trustistecommerceSecurely accept bank transfers, Apple Pay, Google Pay, and card payments on your website using TrustistPay. From only 0.29% per transaction!
Is TrustistEcommerce Safe to Use in 2026?
Generally Safe
Score 92/100TrustistEcommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "trustistecommerce" v1.0.9 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a reduced attack surface. Furthermore, the plugin successfully implements nonce checks on entry points, indicating an effort to mitigate cross-site request forgery. The zero-known CVEs and lack of historical vulnerabilities suggest a mature and well-maintained codebase.
However, a significant concern arises from the taint analysis. Four flows were identified with "unsanitized paths." While the analysis does not report critical or high severity for these, unsanitized paths can be a precursor to injection vulnerabilities if not handled carefully in downstream logic. The absence of capability checks on the entry points is another area for potential improvement, as it implies that any authenticated user, regardless of their role, could potentially interact with these features. The bundled Guzzle library, while not inherently a vulnerability, should be monitored for potential security issues if it becomes outdated.
In conclusion, the plugin is strong in its core secure coding practices. The primary areas for attention are the identified unsanitized paths in the taint analysis and the lack of explicit capability checks on its entry points. Addressing these would further solidify its security, especially considering its otherwise clean history and adherence to best practices.
Key Concerns
- Flows with unsanitized paths identified
- No capability checks on entry points
- Bundled Guzzle library
TrustistEcommerce Security Vulnerabilities
TrustistEcommerce Release Timeline
TrustistEcommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
TrustistEcommerce Attack Surface
AJAX Handlers 4
Shortcodes 4
WordPress Hooks 22
Maintenance & Trust
TrustistEcommerce Maintenance & Trust
Maintenance Signals
Community Trust
TrustistEcommerce Alternatives
Total processing card payments for WooCommerce
totalprocessing-card-payments
Accept Credit Cards and Debit Cards on your WooCommerce store.
ECOMMPAY Payments
ecommpay-payments
Accept bank transfers, cards, local payment methods and cryptocurrencies. Boost conversion with a customisable checkout form.
Metadologie : Payments and Subscriptions
metadologie-payments-and-subscriptions
Accept payments via Metadologie with WooCommerce/WordPress. Features include secure Email Payment Links and a dedicated ACH Bank Transfer portal.
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments
surecart
Make ecommerce easy with a simple-to-use, all-in-one platform that anyone can set up in just a few minutes!
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
TrustistEcommerce Developer Profile
1 plugin · 0 total installs
How We Detect TrustistEcommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trustistecommerce/js/trustistpayments-gravityforms.jstrustistpayments-gravityforms.js?ver=trustist-payments-nonceHTML / DOM Fingerprints
trustist-payments-gravityformsid="payment_status"name="payment_status"id="payment_date"name="payment_date"id="trustist_transaction_id"name="trustist_transaction_id"+3 moreTRUSTISTPLUGIN_VERSIONTRUSTISTPLUGIN_SLUGTRUSTISTPLUGIN_NAMETRUSTISTPLUGIN_FILETRUSTISTPLUGIN_HOOKTRUSTISTPLUGIN_PATH+2 more