Vendreo Card Gateway Security & Risk Analysis

wordpress.org/plugins/vendreo-card-gateway

Vendreo's latest payment solution. Accept card payments online through your WooCommerce store safely and securely.

0 active installs v1.0.7 PHP 7.2+ WP 6.1.1+ Updated Mar 4, 2024
mastercardpayment-gatewaypayment-processingvisawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vendreo Card Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Vendreo Card Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The vendreo-card-gateway plugin v1.0.7 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of unauthenticated entry points, dangerous functions, raw SQL queries, and improperly escaped output are significant strengths. Furthermore, the lack of any recorded vulnerabilities, including critical or high severity ones, and no recent security issues suggest a well-maintained and secure plugin. The plugin also correctly avoids bundled libraries and makes minimal external HTTP requests, both of which are good security practices.

However, there are some areas that warrant attention. The complete absence of nonce checks and capability checks, while not immediately indicative of a vulnerability in this specific analysis due to the lack of entry points, represents a potential weakness. If any new entry points were to be added in the future without proper authentication and authorization mechanisms, these existing gaps could be easily exploited. The presence of file operations and external HTTP requests, although singular, also introduces potential attack vectors that require careful review for improper handling or sanitization, even if current taint analysis shows no issues.

In conclusion, vendreo-card-gateway v1.0.7 appears to be a secure plugin with a clean track record. The development team has clearly implemented good security practices. The only minor concerns stem from the complete lack of nonce and capability checks, which, while not currently exploited, could become a risk if the plugin evolves. The single file operation and external HTTP request should be monitored for any future changes or potential misuse.

Key Concerns

  • No Nonce Checks on entry points
  • No Capability Checks on entry points
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Vendreo Card Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vendreo Card Gateway Release Timeline

v1.0.7Current
v1.0.6
v1.0.5
Code Analysis
Analyzed Apr 16, 2026

Vendreo Card Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0
Attack Surface

Vendreo Card Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_api_card_callbackincludes/php/class-woocommerce-vendreo-card-gateway.php:26
actionplugins_loadedvendreo-card-gateway.php:21
filterwoocommerce_payment_gatewaysvendreo-card-gateway.php:31
actionbefore_woocommerce_initvendreo-card-gateway.php:48
actionwoocommerce_blocks_loadedvendreo-card-gateway.php:49
actionwoocommerce_blocks_payment_method_type_registrationvendreo-card-gateway.php:61
Maintenance & Trust

Vendreo Card Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 4, 2024
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Vendreo Card Gateway Developer Profile

vendreo

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vendreo Card Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Vendreo Card Gateway