Clover Payment Gateway by Zaytech for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-clover-gateway-by-zaytech

Accept Clover POS payments from WooCommerce and auto-print orders to your Clover devices in minutes.

600 active installs v1.3.5 PHP 5.6.0+ WP 6.0+ Updated Dec 17, 2025
cloverclover-posonline-orderingpayment-gatewaywoocommerce
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 22, 2024
Safety Verdict

Is Clover Payment Gateway by Zaytech for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Clover Payment Gateway by Zaytech for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 22, 2024Updated 3mo ago
Risk Assessment

The 'woo-clover-gateway-by-zaytech' plugin version 1.3.5 demonstrates several good security practices, including the absence of dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. It also has a limited attack surface with only one AJAX handler, which appears to be protected. Furthermore, the plugin has no critical or high severity vulnerabilities recorded in its history, and all previously known CVEs are patched.

However, there are areas for concern. The presence of six external HTTP requests could potentially be exploited if not handled carefully, and the single AJAX handler relies on nonce and capability checks, which are positive signs. The plugin has a past medium severity vulnerability related to improper access control, indicating that while current security seems good, past issues suggest a need for continued vigilance. The lack of taint analysis results doesn't necessarily mean no issues exist, but rather that the analysis couldn't identify any exploitable flows based on the methodology used.

In conclusion, the plugin has a generally positive security posture with strong adherence to basic secure coding principles. The absence of critical vulnerabilities and the patching of past issues are commendable. Nevertheless, the history of a medium vulnerability and the presence of external HTTP requests warrant ongoing monitoring and security review to ensure no new weaknesses emerge.

Key Concerns

  • Previous medium severity vulnerability found
  • Six external HTTP requests present
Vulnerabilities
1

Clover Payment Gateway by Zaytech for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-0626medium · 5.3Improper Access Control

WooCommerce Clover Payment Gateway <= 1.3.1 - Missing Authorization via callback_handler

Mar 22, 2024 Patched in 1.3.2 (130d)
Code Analysis
Analyzed Mar 16, 2026

Clover Payment Gateway by Zaytech for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
40 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

91% escaped44 total outputs
Attack Surface

Clover Payment Gateway by Zaytech for WooCommerce Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_woocci_review_actionincludes\woocci_zaytech_rev.php:33
WordPress Hooks 22
actionadmin_enqueue_scriptsincludes\woocci_zaytech_admin.php:24
actioninitincludes\woocci_zaytech_rev.php:32
actionadmin_noticesincludes\woocci_zaytech_rev.php:42
actionnetwork_admin_noticesincludes\woocci_zaytech_rev.php:43
actionuser_admin_noticesincludes\woocci_zaytech_rev.php:44
actionadmin_noticesincludes\woocci_zay_gateway.php:144
actionwp_enqueue_scriptsincludes\woocci_zay_gateway.php:157
actionplugins_loadedzaytech-woo-commerce-clover-integration.php:44
actionbefore_woocommerce_initzaytech-woo-commerce-clover-integration.php:46
actionadmin_noticeszaytech-woo-commerce-clover-integration.php:55
actionadmin_noticeszaytech-woo-commerce-clover-integration.php:63
actionadmin_initzaytech-woo-commerce-clover-integration.php:112
filterwoocommerce_payment_gatewayszaytech-woo-commerce-clover-integration.php:136
filterwoocci_order_customer_notezaytech-woo-commerce-clover-integration.php:140
filterwoocci_line_item_notezaytech-woo-commerce-clover-integration.php:142
actionrest_api_initzaytech-woo-commerce-clover-integration.php:144
actionwoocommerce_order_actionszaytech-woo-commerce-clover-integration.php:146
actionwoocommerce_order_action_woocci_check_payment_orderzaytech-woo-commerce-clover-integration.php:148
actionupdate_option_woocommerce_woocci_zaytech_settingszaytech-woo-commerce-clover-integration.php:150
actionwoocci_process_payment_successzaytech-woo-commerce-clover-integration.php:153
actionwoocommerce_blocks_loadedzaytech-woo-commerce-clover-integration.php:156
actionwoocommerce_blocks_payment_method_type_registrationzaytech-woo-commerce-clover-integration.php:284
Maintenance & Trust

Clover Payment Gateway by Zaytech for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version5.6.0
Downloads25K

Community Trust

Rating68/100
Number of ratings7
Active installs600
Developer Profile

Clover Payment Gateway by Zaytech for WooCommerce Developer Profile

ZAYTECH

2 plugins · 2K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clover Payment Gateway by Zaytech for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/css/admin.css/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/css/style.css/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/js/admin.js/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/js/frontend.js/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/js/clover-payment-gateway.js
Script Paths
/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/js/admin.js/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/js/frontend.js/wp-content/plugins/woo-clover-gateway-by-zaytech/assets/js/clover-payment-gateway.js
Version Parameters
woo-clover-gateway-by-zaytech/assets/css/admin.css?ver=woo-clover-gateway-by-zaytech/assets/css/style.css?ver=woo-clover-gateway-by-zaytech/assets/js/admin.js?ver=woo-clover-gateway-by-zaytech/assets/js/frontend.js?ver=woo-clover-gateway-by-zaytech/assets/js/clover-payment-gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
woocci-clover-gateway-settingswoocci_zaytech_message
HTML Comments
<!-- Clover Payment Gateway by Zaytech for WooCommerce --><!-- Plugin Name: Clover Payment Gateway by Zaytech for WooCommerce -->
Data Attributes
data-clover-envdata-clover-merchant-iddata-clover-api-keydata-clover-pos-location-iddata-clover-app-id
JS Globals
window.woocci_clover_settingsvar woocci_clover_settings
REST Endpoints
/wp-json/woocci/v1/process-payment/wp-json/woocci/v1/check-payment
FAQ

Frequently Asked Questions about Clover Payment Gateway by Zaytech for WooCommerce