Vendreo Open Banking Gateway Security & Risk Analysis

wordpress.org/plugins/vendreo-open-banking-gateway

Vendreo's latest payment solution. Accept Open Banking payments online through your WooCommerce store safely and securely.

0 active installs v2.0.0 PHP 7.2+ WP 6.1.1+ Updated Apr 26, 2024
open-bankingpayment-gatewaypayment-processingwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vendreo Open Banking Gateway Safe to Use in 2026?

Generally Safe

Score 92/100

Vendreo Open Banking Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of vendreo-open-banking-gateway v2.0.0 indicates a generally strong security posture in terms of common attack vectors and code practices. The plugin reports zero AJAX handlers, REST API routes, shortcodes, or cron events, leading to a remarkably small and, based on the data, seemingly protected attack surface. Furthermore, all SQL queries utilize prepared statements, and all output is properly escaped, addressing significant potential vulnerabilities. The absence of dangerous functions and a clean taint analysis further bolsters this positive assessment.

However, there are a few areas that warrant attention and could indicate underlying risks. The presence of file operations and external HTTP requests, while not inherently insecure, represent potential entry points that require diligent secure coding practices to prevent exploitation. The complete absence of nonce checks and capability checks is a notable concern. While the analysis shows no unprotected entry points, the lack of these fundamental WordPress security mechanisms means that even if future functionality is added, it might be introduced without essential safeguards. The plugin's vulnerability history is completely clean, which is excellent, but it's important to note that this might also be due to its current limited scope or the recency of its development. A balanced conclusion would be that the plugin exhibits good foundational security practices for its current state but lacks some critical defensive layers that are standard in more mature or complex plugins.

Key Concerns

  • File operations present
  • External HTTP requests present
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Vendreo Open Banking Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Vendreo Open Banking Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0
Attack Surface

Vendreo Open Banking Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwoocommerce_api_ob_callbackincludes\php\class-woocommerce-vendreo-ob-gateway.php:26
actionplugins_loadedvendreo-open-banking-gateway.php:21
filterwoocommerce_payment_gatewaysvendreo-open-banking-gateway.php:31
actionbefore_woocommerce_initvendreo-open-banking-gateway.php:47
actionwoocommerce_blocks_loadedvendreo-open-banking-gateway.php:48
actionwoocommerce_blocks_payment_method_type_registrationvendreo-open-banking-gateway.php:60
Maintenance & Trust

Vendreo Open Banking Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedApr 26, 2024
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Vendreo Open Banking Gateway Developer Profile

vendreo

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vendreo Open Banking Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Vendreo Open Banking Gateway