
CardCom Payment Gateway Security & Risk Analysis
wordpress.org/plugins/woo-cardcom-payment-gatewayCardcom payment-gateway plugin for WooCommerce.
Is CardCom Payment Gateway Safe to Use in 2026?
Mostly Safe
Score 78/100CardCom Payment Gateway is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "woo-cardcom-payment-gateway" plugin v3.5.0.5 presents a mixed security posture. On the positive side, the static analysis shows no readily identifiable dangerous functions, all SQL queries utilize prepared statements, and there are no detected taint flows. The plugin also demonstrates some good security practices with the presence of nonce and capability checks.
However, significant concerns arise from the output escaping, where only 50% of outputs are properly escaped, leaving potential for Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin has a history of vulnerabilities, including one currently unpatched medium severity CVE. The fact that the last vulnerability was in September 2025 and remains unpatched is a critical red flag, indicating a lack of ongoing maintenance and a potential for exploit. The presence of external HTTP requests without further context also warrants caution.
While the plugin's attack surface appears minimal and it employs some security controls, the unpatched vulnerability and insufficient output escaping significantly lower its overall security standing. Users should exercise extreme caution and prioritize updating or seeking alternative solutions if a patch is not promptly released.
Key Concerns
- Unpatched CVE
- Insufficient Output Escaping
- External HTTP Requests (potential risk)
CardCom Payment Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CardCom Payment Gateway <= 3.5.0.4 - Missing Authorization
CardCom Payment Gateway Code Analysis
Output Escaping
CardCom Payment Gateway Attack Surface
WordPress Hooks 28
Maintenance & Trust
CardCom Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
CardCom Payment Gateway Alternatives
Custom Payment Gateways for WooCommerce
custom-payment-gateways-woocommerce
Custom payment gateways for WooCommerce - create custom payment gateways to never miss out any payments for your WooCommerce Store.
myPOS Checkout
mypos-virtual-for-woocommerce
One-click checkout with instant settlement. Accept all major cards, Apple Pay and Google Pay. No setup costs or monthly fees.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
Payment Gateways by User Roles for WooCommerce
payment-gateways-by-user-roles-for-woocommerce
Set user roles to include/exclude for WooCommerce payment gateways to show up.
imoje
imoje
Add payment via imoje to WooCommerce
CardCom Payment Gateway Developer Profile
1 plugin · 3K total installs
How We Detect CardCom Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-cardcom-payment-gateway/assets/css/cardcom-checkout.css/wp-content/plugins/woo-cardcom-payment-gateway/assets/js/cardcom-checkout.js/wp-content/plugins/woo-cardcom-payment-gateway/assets/js/cardcom-checkout.jswoo-cardcom-payment-gateway/assets/css/cardcom-checkout.css?ver=woo-cardcom-payment-gateway/assets/js/cardcom-checkout.js?ver=HTML / DOM Fingerprints
cardcom-checkout-formdata-cardcom-terminal-idcardcom_checkout_params