
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Security & Risk Analysis
wordpress.org/plugins/wonderful-payments-for-woocommerceAccept Pay by Bank payments in WooCommerce using Open Banking. Instant settlement, lower fees, bank-level security. UK merchants only.
Is Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Safe to Use in 2026?
Generally Safe
Score 100/100Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wonderful-payments-for-woocommerce" plugin v0.8.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history are also encouraging signs, suggesting a relatively stable and well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin exposes two unprotected entry points: one AJAX handler and one REST API route that lacks permission callbacks. This presents a notable attack surface where unauthenticated or unauthorized users could potentially interact with sensitive functionalities. The presence of one flow with an unsanitized path in the taint analysis, while not classified as critical or high, warrants further investigation as it indicates a potential avenue for injection attacks if exploited correctly.
In conclusion, while the plugin benefits from strong data handling and a clear vulnerability history, the exposed, unprotected entry points and the identified unsanitized path are critical weaknesses that elevate the risk profile. These areas require immediate attention to mitigate potential security breaches.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route
- Flow with unsanitized path
- Limited nonce checks
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Security Vulnerabilities
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Code Analysis
Output Escaping
Data Flow Analysis
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 18
Maintenance & Trust
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Maintenance & Trust
Maintenance Signals
Community Trust
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Alternatives
Total processing card payments for WooCommerce
totalprocessing-card-payments
Accept Credit Cards and Debit Cards on your WooCommerce store.
Instant Bank Payments via GoCardless for WooCommerce
wc-gocardless-instant-bank-payments
Take instant bank payments on your WooCommerce store through open banking technology. Increase your conversions, reduce fees, reduce failed payments a …
Vendreo Open Banking Gateway
vendreo-open-banking-gateway
Vendreo's latest payment solution. Accept Open Banking payments online through your WooCommerce store safely and securely.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Wonderful Payments – Pay by Bank and Open Banking for Woo (UK) Developer Profile
1 plugin · 20 total installs
How We Detect Wonderful Payments – Pay by Bank and Open Banking for Woo (UK)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wonderful-payments-for-woocommerce/assets/logo.png/wp-content/plugins/wonderful-payments-for-woocommerce/custom-admin-scripts.js/wp-content/plugins/wonderful-payments-for-woocommerce/wonderful-payments.js/wp-content/plugins/wonderful-payments-for-woocommerce/custom-admin-scripts.js/wp-content/plugins/wonderful-payments-for-woocommerce/wonderful-payments.jswonderful-payments-for-woocommerce/custom-admin-scripts.js?ver=wonderful-payments-for-woocommerce/wonderful-payments.js?ver=HTML / DOM Fingerprints
refund-via-wonderfulwc-order-refund-via-wonderful-itemswc-order-wonderful-logowc-order-successful-refund-panelwc-order-failed-refund-panelwonderful-refund-failure-reasondata-wonderful-payment-iddata-wonderful-order-iddata-wonderful-payment-ref<p><strong>Wonderful Payment ID:</strong><p><strong>Wonderful Order ID:</strong><p><strong>Wonderful Payments Ref:</strong><button type="button" class="button refund-via-wonderful">Refund via Wonderful</button>