Payment Gateway via CIB for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-gateway-cib

With this plugin customers of CIB can accept instant payments through their online stores using the WooCommerce plugin.

100 active installs v1.4 PHP 7.4+ WP 4.0+ Updated Unknown
cibe-commercegatewaypaymentwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway via CIB for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Payment Gateway via CIB for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "wc-gateway-cib" v1.4 demonstrates a generally positive security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed entry points, combined with no recorded vulnerabilities, suggests a limited attack surface and a history of secure development. The use of prepared statements for its single SQL query is a strong indicator of secure database interaction practices. However, the analysis does raise some concerns.

The most significant area of concern is the low percentage of properly escaped output (25%). This indicates that a substantial portion of data being outputted by the plugin might not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Additionally, the complete lack of nonce checks and capability checks on any potential entry points, although currently reported as zero, represents a missed opportunity for fundamental WordPress security best practices. This could become a significant risk if new entry points are introduced in future versions without proper security measures.

Overall, the plugin is currently in a good state due to its limited attack surface and clean vulnerability history. However, the significant portion of unescaped output is a notable weakness that requires attention. If this is not addressed, and especially if the plugin's functionality evolves to include more user interaction or data processing, the risk of security vulnerabilities, particularly XSS, could increase.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Payment Gateway via CIB for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway via CIB for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
12
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

25% escaped16 total outputs
Attack Surface

Payment Gateway via CIB for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedclass-wc-gateway-cib.php:35
actionwoocommerce_thankyouclass-wc-gateway-cib.php:103
actionwoocommerce_view_orderclass-wc-gateway-cib.php:104
actionwoocommerce_admin_order_data_after_order_detailsclass-wc-gateway-cib.php:105
actionwoocommerce_email_after_order_tableclass-wc-gateway-cib.php:106
actionbefore_woocommerce_initclass-wc-gateway-cib.php:107
filterwoocommerce_payment_gatewaysclass-wc-gateway-cib.php:326
actionwoocommerce_api_wc_gateway_cib_return_from_paymentincludes\class-wc-gateway-cib-ipn-handler.php:15
actionwoocommerce_api_wc_gateway_cibincludes\class-wc-gateway-cib-ipn-handler.php:16
Maintenance & Trust

Payment Gateway via CIB for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads4K

Community Trust

Rating86/100
Number of ratings4
Active installs100
Developer Profile

Payment Gateway via CIB for WooCommerce Developer Profile

szathmari

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway via CIB for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-gateway-cib/assets/css/wc-gateway-cib-style.css/wp-content/plugins/wc-gateway-cib/assets/js/wc-gateway-cib-script.js
Script Paths
/wp-content/plugins/wc-gateway-cib/assets/js/wc-gateway-cib-script.js
Version Parameters
wc-gateway-cib/assets/css/wc-gateway-cib-style.css?ver=wc-gateway-cib/assets/js/wc-gateway-cib-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
cib-info
FAQ

Frequently Asked Questions about Payment Gateway via CIB for WooCommerce