Payment Gateway for Paytriot Security & Risk Analysis

wordpress.org/plugins/woo-paytriot-gateway

The Payment Gateway for Paytriot extension provides a completely integrated checkout experience between WooCommerce and Paytriot with extensive types …

20 active installs v1.0.0 PHP 5.6+ WP 5.0+ Updated Feb 1, 2020
paytriotpaytriot-gatewaywoocommercewoocommerce-paytriot
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Payment Gateway for Paytriot Safe to Use in 2026?

Generally Safe

Score 85/100

Payment Gateway for Paytriot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The plugin "woo-paytriot-gateway" v1.0.0 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the code shows good practices in its handling of SQL queries, exclusively using prepared statements. Furthermore, the static analysis indicates a very small attack surface with zero identified entry points that lack authentication or permission checks.

However, significant concerns arise from the taint analysis, which reveals three flows with unsanitized paths. While these flows are not categorized as critical or high severity in the provided data, the presence of unsanitized paths is a strong indicator of potential injection vulnerabilities that could be exploited if proper sanitization or validation is not applied later in the data processing pipeline. Additionally, the output escaping is only 50% proper, meaning half of the outputs are not being escaped, which could lead to cross-site scripting (XSS) vulnerabilities. The single external HTTP request also warrants caution, as it could be a vector for further attacks if not handled securely. The lack of nonce and capability checks on any identified entry points (though there are zero) is a positive, but the presence of unsanitized paths and insufficient output escaping are the most pressing issues.

In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, the identified taint flows and output escaping issues present real risks. The vulnerability history being clear is a good sign, but it does not negate the immediate concerns highlighted by the static and taint analysis. Addressing the unsanitized paths and improving output escaping should be the top priorities.

Key Concerns

  • Flows with unsanitized paths
  • Output escaping is only 50% proper
Vulnerabilities
None known

Payment Gateway for Paytriot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Gateway for Paytriot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped8 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
wpg_gateway_init_gateway_class (woo-paytriot-gateway.php:75)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Payment Gateway for Paytriot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterwoocommerce_payment_gatewayswoo-paytriot-gateway.php:19
actionadd_meta_boxeswoo-paytriot-gateway.php:48
actionplugins_loadedwoo-paytriot-gateway.php:74
actionwp_enqueue_scriptswoo-paytriot-gateway.php:119
actionwoocommerce_api_paytriotwoo-paytriot-gateway.php:122
Maintenance & Trust

Payment Gateway for Paytriot Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 1, 2020
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Payment Gateway for Paytriot Developer Profile

Hassan Ali ⚡️

4 plugins · 350 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Gateway for Paytriot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-paytriot-gateway/images/paytriot-small.png

HTML / DOM Fingerprints

REST Endpoints
/wp-json/paytriot/v1/webhook
FAQ

Frequently Asked Questions about Payment Gateway for Paytriot