Network Merchant Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/webmicro-nmi-woo-addon

This plugin is an addon for WooCommerce to implement a payment gateway method for accepting Credit Cards Payments By merchants through Network Merchan …

100 active installs v1.0.0 PHP + WP + Updated Oct 9, 2016
credit-card-payment-with-woocommerce-and-network-merchantsnetwork-merchants-woocommerce-addonwoocommercewoocommerce-addon-for-network-merchants-payment-gateway
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Network Merchant Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Network Merchant Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "webmicro-nmi-woo-addon" plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis. The absence of any discovered CVEs, coupled with a complete lack of critical or high-severity taint flows, suggests a well-developed and tested codebase. The plugin also adheres to good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its security.

However, there are notable areas for improvement. The complete absence of nonce checks and capability checks across all entry points, although the current entry point count is zero, presents a potential risk. If future updates introduce new entry points, the lack of these fundamental WordPress security mechanisms could lead to vulnerabilities. The single external HTTP request, while not inherently a vulnerability, warrants scrutiny to ensure it is made securely and does not expose the site to risks associated with untrusted external services. The lack of any recorded vulnerability history is positive, but it's important to recognize that this is based on available data and doesn't guarantee future immunity.

In conclusion, the "webmicro-nmi-woo-addon" plugin v1.0.0 is currently in a good security state, primarily due to the absence of known vulnerabilities and the adoption of secure coding practices for its existing features. The main concern lies in the foundational security mechanisms that are absent. While the attack surface is currently minimal, the lack of nonce and capability checks creates a potential weakness that could be exploited if the plugin's functionality expands without addressing these oversights. Continued vigilance and the implementation of these basic security checks are recommended for long-term security.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • External HTTP requests without clear context
Vulnerabilities
None known

Network Merchant Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Network Merchant Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

90% escaped20 total outputs
Attack Surface

Network Merchant Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterwoocommerce_payment_gatewayswebmicro-nmi-woo-addon.php:23
actionplugins_loadedwebmicro-nmi-woo-addon.php:385
Maintenance & Trust

Network Merchant Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedOct 9, 2016
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Network Merchant Payment Gateway for WooCommerce Developer Profile

syednazrulhassan

10 plugins · 540 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Network Merchant Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webmicro-nmi-woo-addon/images/amex.png/wp-content/plugins/webmicro-nmi-woo-addon/images/dinersclub.png/wp-content/plugins/webmicro-nmi-woo-addon/images/discover.png/wp-content/plugins/webmicro-nmi-woo-addon/images/jcb.png/wp-content/plugins/webmicro-nmi-woo-addon/images/mastercard.png/wp-content/plugins/webmicro-nmi-woo-addon/images/nmi.png/wp-content/plugins/webmicro-nmi-woo-addon/images/visa.png

HTML / DOM Fingerprints

CSS Classes
nmigateway
FAQ

Frequently Asked Questions about Network Merchant Payment Gateway for WooCommerce