Pelecard Gateway Security & Risk Analysis

wordpress.org/plugins/woo-pelecard-gateway

Extends WooCommerce with Pelecard payment gateway.

500 active installs v1.5.2 PHP 7.0+ WP 5.5+ Updated Feb 24, 2026
checkoutcredit-cardpaymentspelecardwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Pelecard Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

Pelecard Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "woo-pelecard-gateway" plugin version 1.5.2 exhibits a generally good security posture, with strong practices in SQL query handling and output escaping. The plugin successfully utilizes prepared statements for all SQL queries and demonstrates a high rate of proper output escaping, which are crucial for preventing common web vulnerabilities. The absence of recorded vulnerabilities and CVEs in its history further suggests a diligent approach to security by the developers. However, there are notable areas of concern, primarily revolving around its attack surface. The presence of two AJAX handlers that lack authentication checks represents a significant potential entry point for malicious actors. While no critical taint flows were identified, and no raw SQL queries were found, these unprotected AJAX handlers could allow for unauthorized actions or information disclosure if not properly validated and secured within their implementation.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

Pelecard Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pelecard Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
18 prepared
Unescaped Output
4
119 escaped
Nonce Checks
2
Capability Checks
2
File Operations
2
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared18 total queries

Output Escaping

97% escaped123 total outputs
Attack Surface
2 unprotected

Pelecard Gateway Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_wppc_check_order_statusincludes\Gateway.php:239
noprivwp_ajax_wppc_check_order_statusincludes\Gateway.php:240
authwp_ajax_wppc_charge_orderincludes\Order.php:282
authwp_ajax_update_dataincludes\Plugin.php:25
WordPress Hooks 37
actionadmin_enqueue_scriptsincludes\Gateway.php:223
actionadmin_headincludes\Gateway.php:224
actionadmin_noticesincludes\Gateway.php:225
actionbefore_woocommerce_payincludes\Gateway.php:234
actionwoocommerce_review_order_before_paymentincludes\Gateway.php:235
actionwoocommerce_checkout_update_order_reviewincludes\Gateway.php:236
filterwoocommerce_credit_card_type_labelsincludes\Gateway.php:242
filterwcml_gateway_text_keys_to_translateincludes\Gateway.php:244
filterwppc/transaction/needs_validationincludes\Gateway.php:246
actioninitincludes\Invoices\Base.php:18
filterwppc/settings/admin_fieldsincludes\Invoices\Base.php:19
filterwppc/checkout/rest_argsincludes\Invoices\Base.php:24
filterwppc/checkout/iframe_argsincludes\Invoices\Base.php:25
actionadmin_menuincludes\Legacy.php:20
actionwppc/transaction/after_saveincludes\Legacy.php:21
actionadmin_noticesincludes\Legacy.php:31
actionadmin_initincludes\Order.php:13
actionadd_meta_boxesincludes\Order.php:16
actionadd_meta_boxes_shop_orderincludes\Order.php:17
actionadd_meta_boxes_woocommerce_page_wc-ordersincludes\Order.php:18
actionadmin_enqueue_scriptsincludes\Order.php:20
actionwoocommerce_order_item_add_action_buttonsincludes\Order.php:21
actionwp_enqueue_scriptsincludes\Plugin.php:22
actionadmin_initincludes\Plugin.php:24
filterwoocommerce_payment_gatewaysincludes\Plugin.php:27
actionwoocommerce_blocks_loadedincludes\Plugin.php:30
actionwp_footerincludes\Plugin.php:33
actioninitincludes\Plugin.php:208
actionwpincludes\Plugin.php:209
actionwoocommerce_blocks_payment_method_type_registrationincludes\Plugin.php:268
filterall_pluginspelecard-gateway.php:56
actionbefore_woocommerce_initpelecard-gateway.php:62
actionupgrader_process_completepelecard-gateway.php:70
actionadmin_noticespelecard-gateway.php:107
actionplugins_loadedpelecard-gateway.php:124
actioninitpelecard-gateway.php:127
actionadmin_noticespelecard-gateway.php:148
Maintenance & Trust

Pelecard Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version7.0
Downloads21K

Community Trust

Rating100/100
Number of ratings3
Active installs500
Developer Profile

Pelecard Gateway Developer Profile

Pelecard

1 plugin · 500 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pelecard Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-pelecard-gateway/assets/css/pelecard-gateway-admin.css/wp-content/plugins/woo-pelecard-gateway/assets/js/pelecard-gateway-admin.js/wp-content/plugins/woo-pelecard-gateway/assets/js/card-validation.js/wp-content/plugins/woo-pelecard-gateway/assets/js/pelecard-gateway.js/wp-content/plugins/woo-pelecard-gateway/assets/css/pelecard-gateway.css
Script Paths
/wp-content/plugins/woo-pelecard-gateway/assets/js/pelecard-gateway-admin.js/wp-content/plugins/woo-pelecard-gateway/assets/js/card-validation.js/wp-content/plugins/woo-pelecard-gateway/assets/js/pelecard-gateway.js
Version Parameters
woo-pelecard-gateway/assets/css/pelecard-gateway-admin.css?ver=woo-pelecard-gateway/assets/js/pelecard-gateway-admin.js?ver=woo-pelecard-gateway/assets/js/card-validation.js?ver=woo-pelecard-gateway/assets/js/pelecard-gateway.js?ver=woo-pelecard-gateway/assets/css/pelecard-gateway.css?ver=

HTML / DOM Fingerprints

CSS Classes
pelecard-gateway-card-wrapperpelecard-gateway-input-fieldpelecard-gateway-icon
HTML Comments
<!-- Pelecard Payment Gateway Settings -->
Data Attributes
data-pelecard-gateway-urldata-pelecard-gateway-public-key
JS Globals
pelecardGatewaySettings
REST Endpoints
/wp-json/pelecardwc/v1/tokenize
FAQ

Frequently Asked Questions about Pelecard Gateway