Payment Gateway for Sparco on WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-sparco-payment-gateway

The plugin allows merchants to accept Visa, Mastercard, MTN Mobile Money Zambia, Airtel Money Zambia and Zamkwacha payments.

20 active installs v1.0.0 PHP 5.6+ WP 4.0.1+ Updated Mar 11, 2021
mastercardmobile-moneysparcovisawoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for Sparco on WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for Sparco on WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of wc-sparco-payment-gateway v1.0.0 reveals a generally positive security posture. The plugin demonstrates good practices by not exposing any direct entry points like AJAX handlers, REST API routes, or shortcodes without authentication checks, and all SQL queries are performed using prepared statements. Furthermore, all identified output operations are properly escaped, and there are no critical or high severity taint flows. This indicates a conscientious effort by the developers to follow secure coding principles.

However, there are a few areas that warrant attention and contribute to a minor risk. The plugin performs one file operation and one external HTTP request, which, while not inherently insecure, represent potential attack vectors if not handled with utmost care in their implementation. Crucially, the absence of nonce checks and capability checks on any potential (though unlisted) entry points is a significant concern. While the static analysis reports zero unprotected entry points, the lack of these fundamental security mechanisms implies that if any such points were to exist or be introduced in future versions, they would be immediately vulnerable to various attacks like Cross-Site Request Forgery (CSRF).

The vulnerability history is entirely clean, with no recorded CVEs. This is an excellent sign and suggests a stable and relatively secure past. However, the lack of past vulnerabilities does not guarantee future security, especially given the identified areas for improvement. The overall risk is moderate due to the absence of critical vulnerabilities in the current analysis and history, but the potential for significant risk exists if the identified gaps in authentication and authorization are exploited or overlooked.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • Potential risk from file operation
  • Potential risk from external HTTP request
Vulnerabilities
None known

Payment Gateway for Sparco on WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for Sparco on WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Payment Gateway for Sparco on WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwoocommerce_payment_complete_order_statusincludes\class-wc-sparco-payment-gateway.php:44
actionwoocommerce_api_wc_gateway_sparcoincludes\class-wc-sparco-payment-gateway.php:47
actionplugins_loadedwoo-sparco.php:28
filterwoocommerce_payment_gatewayswoo-sparco.php:39
Maintenance & Trust

Payment Gateway for Sparco on WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 11, 2021
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Payment Gateway for Sparco on WooCommerce Developer Profile

glidematrix

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for Sparco on WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-sparco-payment-gateway/assets/images/logo-icon-mini.png

HTML / DOM Fingerprints

Data Attributes
data-placeholder="Select shipping methods"
REST Endpoints
/wp-json/wc-sparco-payment-gateway/v1/checkout
FAQ

Frequently Asked Questions about Payment Gateway for Sparco on WooCommerce