Boldwallet WooCommerce Payment Gateway Security & Risk Analysis

wordpress.org/plugins/woo-boldwallet-boldwallet

Boldwallet WooCommerce Payment Gateway allows you to accept online payments from local and international customers

0 active installs v1.4 PHP + WP 4.7+ Updated May 26, 2020
boldwalletmastercardpayment-gatewayvervevisa
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Boldwallet WooCommerce Payment Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

Boldwallet WooCommerce Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "woo-boldwallet-boldwallet" plugin version 1.4 exhibits a mixed security posture. On the positive side, the static analysis indicates no direct SQL injection risks due to the exclusive use of prepared statements, and there are no known historical vulnerabilities (CVEs). The attack surface is reported as zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, which is a significant strength. However, several concerns arise from the code signals. A notable percentage of output (57%) is not properly escaped, presenting a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is output without proper sanitization. The presence of an external HTTP request also warrants scrutiny, as it could be a vector for various attacks if not handled securely. Furthermore, the taint analysis revealing three flows with unsanitized paths, while not flagged as critical or high severity, suggests potential weaknesses in input validation or sanitization that could be exploited in specific scenarios. The complete absence of nonce and capability checks, especially if there are hidden entry points not captured by the static analysis, is a significant concern for authorization and integrity.

Key Concerns

  • Significant unescaped output detected
  • Taint flows with unsanitized paths found
  • External HTTP request present
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Boldwallet WooCommerce Payment Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Boldwallet WooCommerce Payment Gateway Release Timeline

v1.4Current
v1.3
Code Analysis
Analyzed Mar 17, 2026

Boldwallet WooCommerce Payment Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

43% escaped7 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
bolwallet_init_gateway_class (woo-boldwallet.php:124)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Boldwallet WooCommerce Payment Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitwoo-boldwallet.php:49
actionadmin_menuwoo-boldwallet.php:50
actionadmin_enqueue_scriptswoo-boldwallet.php:53
filterwoocommerce_payment_gatewayswoo-boldwallet.php:117
actionplugins_loadedwoo-boldwallet.php:121
actionwoocommerce_update_options_payment_gatewayswoo-boldwallet.php:178
actioninitwoo-boldwallet.php:181
actionadmin_enqueue_scriptswoo-boldwallet.php:184
actionwoocommerce_receipt_bwalletpay1woo-boldwallet.php:188
filterplugin_action_linkswoo-boldwallet.php:661
Maintenance & Trust

Boldwallet WooCommerce Payment Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 26, 2020
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Boldwallet WooCommerce Payment Gateway Developer Profile

Mr.software

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Boldwallet WooCommerce Payment Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-boldwallet-boldwallet/assets/mystyle.css/wp-content/plugins/woo-boldwallet-boldwallet/assets/mystyle.js
Script Paths
/wp-content/plugins/woo-boldwallet-boldwallet/assets/mystyle.js
Version Parameters
woo-boldwallet-boldwallet/assets/mystyle.css?ver=woo-boldwallet-boldwallet/assets/mystyle.js?ver=

HTML / DOM Fingerprints

CSS Classes
payboldwallet_payment_form
Data Attributes
id="submit_payboldwallet_payment_form"name="txnid"name="total"name="customerFirstName"name="customerEmail"name="customerPhoneNumber"+14 more
JS Globals
bwalletpay1
REST Endpoints
/wp-json/wc/v3/orders
Shortcode Output
<input type='hidden' name='txnid'<input type='hidden' name='total'<input type='hidden' name='customerFirstName'<input type='hidden' name='customerEmail'
FAQ

Frequently Asked Questions about Boldwallet WooCommerce Payment Gateway