
Payment Gateway SMBCGP for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-smbcgp-gatewayThis plugin adds the functionality to take SMBCGP payments on your store of WooCommerce.
Is Payment Gateway SMBCGP for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Payment Gateway SMBCGP for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wc-smbcgp-gateway" plugin, in version 0.1.1, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and SQL queries that are not properly prepared are excellent indicators of secure coding practices. The high percentage of properly escaped output further mitigates risks of cross-site scripting (XSS). Furthermore, the plugin has no known vulnerabilities, historical or present, which is a significant positive.
However, there are several areas that warrant caution. The presence of 4 "flows with unsanitized paths" in the taint analysis, even without critical or high severity flags, suggests potential for unintended data handling, especially given the absence of capability checks and nonce checks. The plugin also makes 12 external HTTP requests, which could be a vector for vulnerabilities if not handled securely, especially if the target servers are compromised or if the requests are constructed using unsanitized input. The complete lack of capability and nonce checks on any entry points, while the attack surface is currently zero, leaves the plugin highly exposed should any new entry points be introduced without these crucial security mechanisms.
In conclusion, the plugin demonstrates good foundational security with regards to common pitfalls like SQL injection and XSS. Its clean vulnerability history is a major strength. However, the identified unsanitized paths and the complete absence of capability/nonce checks represent significant potential risks that need to be addressed to ensure robust security, particularly as the plugin evolves.
Key Concerns
- Taint flows with unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
- External HTTP requests without checks
Payment Gateway SMBCGP for WooCommerce Security Vulnerabilities
Payment Gateway SMBCGP for WooCommerce Release Timeline
Payment Gateway SMBCGP for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Payment Gateway SMBCGP for WooCommerce Attack Surface
WordPress Hooks 17
Maintenance & Trust
Payment Gateway SMBCGP for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Payment Gateway SMBCGP for WooCommerce Alternatives
Payment Gateway GMOPG for WooCommerce
wc-gmopg-gateway
This plugin adds the functionality to take GMOPG payments on your store of WooCommerce.
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
Payment Gateway SMBCGP for WooCommerce Developer Profile
13 plugins · 43K total installs
How We Detect Payment Gateway SMBCGP for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wcpg-smbcgp-gateway