
Безопасные переводы Тинькофф для WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-tinkoff-secure-deal-payment-gatewayАвтоматизируйте и защитите переводы ваших клиентов с помощью плагина для безопасных сделок от эквайрингового сервиса Тинькофф Кассы.
Is Безопасные переводы Тинькофф для WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Безопасные переводы Тинькофф для WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wc-tinkoff-secure-deal-payment-gateway" version 1.0.1 presents a significant security risk due to its handling of entry points. While the plugin demonstrates good practices in database interaction with 100% prepared statements for SQL queries and has no known vulnerability history, the presence of 4 AJAX handlers without any authentication or capability checks is a major concern. This means any user, regardless of their role or logged-in status, can trigger these AJAX actions, opening a substantial attack surface to potential manipulation.
Furthermore, the taint analysis indicates 2 flows with unsanitized paths, which, although not classified as critical or high severity, still represent a risk. The lack of nonce checks on AJAX handlers exacerbates this by allowing these potentially unsanitized flows to be triggered without proper validation. While the plugin avoids dangerous functions and file operations, and external HTTP requests are present, the primary weakness lies in the unprotected AJAX endpoints and the identified unsanitized data flows. The absence of known CVEs is a positive sign, suggesting a generally well-maintained codebase in terms of historical security issues, but it doesn't mitigate the immediate risks posed by the current static and taint analysis findings.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without capability checks
- Flows with unsanitized paths
- Missing nonce checks on AJAX
- Output escaping partially handled
Безопасные переводы Тинькофф для WooCommerce Security Vulnerabilities
Безопасные переводы Тинькофф для WooCommerce Release Timeline
Безопасные переводы Тинькофф для WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Безопасные переводы Тинькофф для WooCommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 12
Maintenance & Trust
Безопасные переводы Тинькофф для WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Безопасные переводы Тинькофф для WooCommerce Alternatives
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Безопасные переводы Тинькофф для WooCommerce Developer Profile
7 plugins · 60 total installs
How We Detect Безопасные переводы Тинькофф для WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-tinkoff-secure-deal-payment-gateway/assets/images/logo.png/wp-content/plugins/wc-tinkoff-secure-deal-payment-gateway/assets/js/scripts.jsHTML / DOM Fingerprints
wp_ajax/wp-json/wc-tinkoff-secure-deal-payment-gateway/