Shetab Card Field For WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-iran-shetab-card-field

Adding a field for receiving Shetab card number for WooCommerce

10 active installs v2.1.4 PHP 7.4+ WP 6.0+ Updated Feb 13, 2026
checkoutorderpayment-gatewayspaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shetab Card Field For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Shetab Card Field For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "woo-iran-shetab-card-field" plugin v2.1.4 demonstrates a generally strong security posture based on the provided static analysis. There are no detected AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the plugin's attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. The plugin also utilizes prepared statements for all SQL queries, which is a critical security practice. Nonce checks are present, which is another positive indicator of security awareness.

However, there are some areas for concern. The output escaping is only properly implemented for 63% of the outputs, meaning a significant portion (37%) could be vulnerable to cross-site scripting (XSS) attacks if user-supplied data is directly outputted without proper sanitization. The lack of capability checks on any entry points, while the entry points themselves are currently zero, represents a potential future risk if new entry points are introduced without proper authorization checks. The vulnerability history being entirely clear is a positive sign, suggesting a history of responsible development or a lack of targeted attacks, but it does not negate the potential risks identified in the static analysis.

In conclusion, the plugin has several strengths, particularly in its minimal attack surface and secure database interaction. The primary weakness lies in the incomplete output escaping, which poses a tangible risk. The absence of capability checks also presents a potential, albeit less immediate, concern. Addressing the output escaping issue should be a priority to improve the overall security of the plugin.

Key Concerns

  • Output escaping not properly implemented
Vulnerabilities
None known

Shetab Card Field For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shetab Card Field For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped8 total outputs
Attack Surface

Shetab Card Field For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsincludes\ShetabCardField\class-shetab-card-field.php:81
actionwp_enqueue_scriptsincludes\ShetabCardField\class-shetab-card-field.php:84
actionwoocommerce_after_order_notesincludes\ShetabCardField\class-shetab-card-field.php:87
actionwoocommerce_checkout_processincludes\ShetabCardField\class-shetab-card-field.php:88
actionwoocommerce_checkout_update_order_metaincludes\ShetabCardField\class-shetab-card-field.php:89
actionwoocommerce_admin_order_data_after_billing_addressincludes\ShetabCardField\class-shetab-card-field.php:90
filterwoocommerce_email_order_meta_keysincludes\ShetabCardField\class-shetab-card-field.php:91
Maintenance & Trust

Shetab Card Field For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version7.4
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shetab Card Field For WooCommerce Developer Profile

ParsMizban

4 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shetab Card Field For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-iran-shetab-card-field/assets/public/css/style.css/wp-content/plugins/woo-iran-shetab-card-field/assets/public/css/style.rtl.css/wp-content/plugins/woo-iran-shetab-card-field/assets/admin/css/style.css/wp-content/plugins/woo-iran-shetab-card-field/assets/admin/css/style.rtl.css/wp-content/plugins/woo-iran-shetab-card-field/assets/public/js/script.js/wp-content/plugins/woo-iran-shetab-card-field/assets/admin/js/script.js
Script Paths
/wp-content/plugins/woo-iran-shetab-card-field/assets/public/js/script.js/wp-content/plugins/woo-iran-shetab-card-field/assets/admin/js/script.js
Version Parameters
woo-iran-shetab-card-field/assets/public/css/style.css?ver=woo-iran-shetab-card-field/assets/public/css/style.rtl.css?ver=woo-iran-shetab-card-field/assets/admin/css/style.css?ver=woo-iran-shetab-card-field/assets/admin/css/style.rtl.css?ver=woo-iran-shetab-card-field/assets/public/js/script.js?ver=woo-iran-shetab-card-field/assets/admin/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
shetab-card-field-classshetab-card-field-person-classform-row-wide
Data Attributes
shetab_card_info_nonce
Shortcode Output
<div id="shetab_card_number_field"><h2>Your Shetab card number</h2><br />
FAQ

Frequently Asked Questions about Shetab Card Field For WooCommerce