Gateway for Wise on WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-wise-gateway

A simple WooCommerce payment gateway for Wise (formerly TransferWise)

1K active installs v2.2.2 PHP 7.0+ WP 5.0+ Updated Jan 7, 2026
bank-transfercheckouttransferwisewirewise
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gateway for Wise on WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Gateway for Wise on WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the static analysis, the "wc-wise-gateway" v2.2.2 plugin exhibits a generally good security posture. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin demonstrates adherence to secure coding practices by avoiding dangerous functions, conducting all SQL queries using prepared statements, and performing no file operations or external HTTP requests. The lack of registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. However, the low percentage of properly escaped output (63%) is a concern, as it suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed. While no specific taint flows were identified, the unescaped output areas warrant careful review. The plugin's strengths lie in its minimal attack surface and secure data handling for database operations. The primary weakness is the potential for XSS due to insufficient output escaping.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Gateway for Wise on WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gateway for Wise on WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped43 total outputs
Attack Surface

Gateway for Wise on WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwoocommerce_email_before_order_tableincludes\class-ew-gateway-wise.php:106
actionplugins_loadedwc-wise-gateway.php:25
actionadmin_noticeswc-wise-gateway.php:27
filterwoocommerce_payment_gatewayswc-wise-gateway.php:37
actionbefore_woocommerce_initwc-wise-gateway.php:47
Maintenance & Trust

Gateway for Wise on WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 7, 2026
PHP min version7.0
Downloads20K

Community Trust

Rating100/100
Number of ratings3
Active installs1K
Developer Profile

Gateway for Wise on WooCommerce Developer Profile

alx359

2 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gateway for Wise on WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-wise-gateway/includes/class-ew-gateway-wise.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Gateway for Wise on WooCommerce