
Payment gateway – Robokassa for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-robokassaIntegration Robokassa in WooCommerce as payment gateway plugin.
Is Payment gateway – Robokassa for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Payment gateway – Robokassa for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-robokassa" v4.1.0 plugin presents a mixed security posture. On one hand, the plugin exhibits excellent practices by having no apparent entry points exposed through AJAX, REST API, shortcodes, or cron events without proper authentication checks. Furthermore, it has a clean vulnerability history with no known CVEs, suggesting a generally well-maintained codebase. The presence of capability checks and a reasonable percentage of properly escaped outputs are also positive indicators.
However, several concerning signals are present in the static analysis. The use of the `unserialize()` function is a significant risk, as it can lead to Remote Code Execution if an attacker can control the serialized data. Coupled with this is the fact that 100% of SQL queries are not using prepared statements, which opens the door to SQL injection vulnerabilities. The absence of nonce checks on any entry points, although the attack surface is reported as zero, is a weakness that could become a liability if new entry points are introduced without proper security measures. The taint analysis, while showing no critical or high severity flows, did identify one flow with an unsanitized path, which warrants further investigation.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and a minimal exposed attack surface, the presence of `unserialize()` and raw SQL queries are serious security concerns that significantly detract from its overall security. These issues require immediate attention and remediation to mitigate potential risks.
Key Concerns
- Unsanitized taint flow detected
- Dangerous function: unserialize() used
- 100% of SQL queries not using prepared statements
- 0 Nonce checks found
Payment gateway – Robokassa for WooCommerce Security Vulnerabilities
Payment gateway – Robokassa for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Payment gateway – Robokassa for WooCommerce Attack Surface
WordPress Hooks 31
Maintenance & Trust
Payment gateway – Robokassa for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Payment gateway – Robokassa for WooCommerce Alternatives
Robokassa payment gateway for Woocommerce
robokassa
Позволяет использовать интерфейс (платежный шлюз) для оплаты через Робокассу в WooCommerce. Поддерживает интеграцию чеков (закон 54-ФЗ)
Robokassa for WooCommerce
robokassa-for-woocommerce
Allows you to use Robokassa payment gateway with the WooCommerce plugin.
Robokassa Payment Gateway (Saphali)
robokassa-payment-gateway-saphali
Allows you to use Robokassa payment gateway with the WooCommerce plugin.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Payment gateway – Robokassa for WooCommerce Developer Profile
2 plugins · 400 total installs
How We Detect Payment gateway – Robokassa for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-robokassa/assets/css/wc_robokassa_main.css/wp-content/plugins/wc-robokassa/assets/js/wc_robokassa_main.js/wp-content/plugins/wc-robokassa/assets/js/wc_robokassa_main.jswc-robokassa/assets/css/wc_robokassa_main.css?ver=wc-robokassa/assets/js/wc_robokassa_main.js?ver=HTML / DOM Fingerprints
wc-robokassa-method-titledata-shop-logindata-robokassa-success-urldata-robokassa-fail-urldata-robokassa-invoicedata-robokassa-amountdata-robokassa-currency+10 morewc_robokassa_params/wp-json/wc-robokassa/v1/payment-notify