Stan, la solution de paiement sans carte Security & Risk Analysis

wordpress.org/plugins/wc-stan-payment-gateway

Boostez votre taux de conversion, paiement sans carte et checkout plus rapide. Faites plaisir à vos clients ! Optimisez vos ventes en ligne Adoptez l …

10 active installs v2.7.10 PHP + WP 5.0.0+ Updated Sep 29, 2023
cartcheckoutpaymentpayment-gatewaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stan, la solution de paiement sans carte Safe to Use in 2026?

Generally Safe

Score 85/100

Stan, la solution de paiement sans carte has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of wc-stan-payment-gateway v2.7.10 reveals a mixed security posture. While the plugin demonstrates good practices by having no identified dangerous functions, no raw SQL queries, and no file operations, several concerning areas emerge. The plugin has a significant percentage of unescaped output (59%), which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before display. Furthermore, the taint analysis indicates flows with unsanitized paths, although these did not reach critical or high severity in the provided analysis, they still represent a potential risk. The absence of any nonce checks or capability checks on any entry points is a major concern, leaving all functionalities potentially accessible without proper authorization or validation, which could facilitate various attacks if a vulnerable entry point is discovered. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign suggesting a diligent development or review process in the past. However, the current static analysis findings, particularly the unescaped output and lack of authorization checks, present immediate risks that should not be overlooked. The plugin's strengths lie in its SQL handling and lack of dangerous functions, but its weaknesses in output sanitization and access control are significant.

Key Concerns

  • Significant unescaped output detected
  • Taint flows with unsanitized paths
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Stan, la solution de paiement sans carte Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Stan, la solution de paiement sans carte Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

41% escaped17 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
callback_order (includes\class-wc-stan-payment-gateway.php:494)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Stan, la solution de paiement sans carte Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 36
actionwoocommerce_api_wc_stan_paymentincludes\class-wc-stan-payment-gateway.php:116
filterwoocommerce_gateway_titleincludes\class-wc-stan-payment-gateway.php:118
filterwoocommerce_available_payment_gatewaysincludes\class-wc-stan-payment-gateway.php:119
actionplugins_loadedincludes\class-wc-stan-payment-gateway.php:243
actionadmin_enqueue_scriptsincludes\class-wc-stan-payment-gateway.php:289
actionadmin_enqueue_scriptsincludes\class-wc-stan-payment-gateway.php:290
filterwoocommerce_order_actionsincludes\class-wc-stan-payment-gateway.php:292
actionwoocommerce_order_action_wc_check_payment_and_update_orderincludes\class-wc-stan-payment-gateway.php:293
actionwp_enqueue_scriptsincludes\class-wc-stan-payment-gateway.php:308
actionwp_enqueue_scriptsincludes\class-wc-stan-payment-gateway.php:309
actionwoocommerce_login_form_startincludes\class-wc-stan-payment-gateway.php:378
actionwoocommerce_before_checkout_billing_formincludes\class-wc-stan-payment-gateway.php:379
actionwoocommerce_login_formwoo-stan-pay\includes\class-wc-stan-payment-gateway.php:123
actionwoocommerce_before_checkout_billing_formwoo-stan-pay\includes\class-wc-stan-payment-gateway.php:127
actionwoocommerce_api_wc_stan_paymentwoo-stan-pay\includes\class-wc-stan-payment-gateway.php:134
filterwoocommerce_gateway_titlewoo-stan-pay\includes\class-wc-stan-payment-gateway.php:136
filterwoocommerce_available_payment_gatewayswoo-stan-pay\includes\class-wc-stan-payment-gateway.php:137
actionplugins_loadedwoo-stan-pay\includes\class-wc-stan-payment-gateway.php:261
actionadmin_enqueue_scriptswoo-stan-pay\includes\class-wc-stan-payment-gateway.php:307
actionadmin_enqueue_scriptswoo-stan-pay\includes\class-wc-stan-payment-gateway.php:308
filterwoocommerce_order_actionswoo-stan-pay\includes\class-wc-stan-payment-gateway.php:310
actionwoocommerce_order_action_wc_check_payment_and_update_orderwoo-stan-pay\includes\class-wc-stan-payment-gateway.php:311
actionwp_enqueue_scriptswoo-stan-pay\includes\class-wc-stan-payment-gateway.php:326
actionwp_enqueue_scriptswoo-stan-pay\includes\class-wc-stan-payment-gateway.php:327
filterwoocommerce_payment_gatewayswoo-stan-pay\woo-stan-payment-gateway.php:84
actionplugins_loadedwoo-stan-pay\woo-stan-payment-gateway.php:98
actionadmin_noticeswoo-stan-pay\woo-stan-payment-gateway.php:114
filterplugin_action_links_woo-stan-payment-gateway/woo-stan-payment-gateway.phpwoo-stan-pay\woo-stan-payment-gateway.php:133
filterplugin_action_links_woo-stan-pay/woo-stan-payment-gateway.phpwoo-stan-pay\woo-stan-payment-gateway.php:134
filterplugin_action_links_wc-stan-payment-gateway/woo-stan-payment-gateway.phpwoo-stan-pay\woo-stan-payment-gateway.php:135
filterwoocommerce_payment_gatewayswoo-stan-payment-gateway.php:84
actionplugins_loadedwoo-stan-payment-gateway.php:98
actionadmin_noticeswoo-stan-payment-gateway.php:114
filterplugin_action_links_woo-stan-payment-gateway/woo-stan-payment-gateway.phpwoo-stan-payment-gateway.php:135
filterplugin_action_links_woo-stan-pay/woo-stan-payment-gateway.phpwoo-stan-payment-gateway.php:136
filterplugin_action_links_wc-stan-payment-gateway/woo-stan-payment-gateway.phpwoo-stan-payment-gateway.php:137
Maintenance & Trust

Stan, la solution de paiement sans carte Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedSep 29, 2023
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Stan, la solution de paiement sans carte Developer Profile

Jonathan - CTO Brightweb

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stan, la solution de paiement sans carte

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-stan-payment-gateway/assets/css/admin.css/wp-content/plugins/wc-stan-payment-gateway/assets/js/admin.js/wp-content/plugins/wc-stan-payment-gateway/assets/js/frontend.js
Script Paths
/wp-content/plugins/wc-stan-payment-gateway/assets/js/admin.js/wp-content/plugins/wc-stan-payment-gateway/assets/js/frontend.js
Version Parameters
wc-stan-payment-gateway/assets/css/admin.css?ver=wc-stan-payment-gateway/assets/js/admin.js?ver=wc-stan-payment-gateway/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc-stan-payment-gateway-form
Data Attributes
data-stan-gateway-urldata-stan-merchant-iddata-stan-public-keydata-stan-order-iddata-stan-amountdata-stan-currency+2 more
JS Globals
WC_Stan_Payment_Gateway_Frontend
FAQ

Frequently Asked Questions about Stan, la solution de paiement sans carte