
Sofortueberweisung Gateway for Woocommerce Security & Risk Analysis
wordpress.org/plugins/woo-sofortuberweisung-gatewayAllows your users to pay over Sofortüberweisung via WooCommerce checkout. Easy, fast and safe. Setup is very easy.
Is Sofortueberweisung Gateway for Woocommerce Safe to Use in 2026?
Generally Safe
Score 85/100Sofortueberweisung Gateway for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-sofortuberweisung-gateway" plugin v1.3.4 presents a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL injection, utilizing prepared statements exclusively, and it has no recorded vulnerability history, suggesting a generally stable codebase. The lack of registered CVEs and its most recent vulnerability being unrecorded further bolster this impression.
However, the static analysis reveals significant areas of concern. The most critical finding is the presence of three unsanitized path flows, indicating potential for directory traversal or unintended file access vulnerabilities. Additionally, the very low percentage of properly escaped output (5%) is a substantial risk, exposing the application to cross-site scripting (XSS) attacks. The absence of any nonce or capability checks across the entire plugin, coupled with the lack of authentication checks on any entry points (though the attack surface is zero), suggests a general disregard for input validation and authorization mechanisms. While the current attack surface is zero, any future additions without proper checks could be immediately exploitable.
In conclusion, while the plugin's SQL handling and lack of historical vulnerabilities are strong points, the identified unsanitized paths and pervasive lack of output escaping and authorization checks introduce critical security weaknesses. The potential for XSS and file access vulnerabilities, combined with a lack of fundamental security checks, means this plugin requires immediate attention despite its clean history.
Key Concerns
- Unsanitized path flows found
- Very low output escaping percentage
- No nonce checks implemented
- No capability checks implemented
Sofortueberweisung Gateway for Woocommerce Security Vulnerabilities
Sofortueberweisung Gateway for Woocommerce Release Timeline
Sofortueberweisung Gateway for Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Sofortueberweisung Gateway for Woocommerce Attack Surface
WordPress Hooks 8
Maintenance & Trust
Sofortueberweisung Gateway for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Sofortueberweisung Gateway for Woocommerce Alternatives
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Sofortueberweisung Gateway for Woocommerce Developer Profile
8 plugins · 21K total installs
How We Detect Sofortueberweisung Gateway for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-sofortuberweisung-gateway/core/klarna.svg/wp-content/plugins/woo-sofortuberweisung-gateway/core/sofort-logo.pngwoo-sofortuberweisung-gateway/woo-sofortuberweisung-gateway.php?ver=woo-sofortuberweisung-gateway/sofort/core/sofortLibSofortueberweisung.inc.php?ver=woo-sofortuberweisung-gateway/sofort/core/sofortLibNotification.inc.php?ver=woo-sofortuberweisung-gateway/sofort/core/sofortLibTransactionData.inc.php?ver=HTML / DOM Fingerprints
notice-infoVERY IMPORTANTIt was detected that you are using the plugin Germanized for WooCommerce.You have activated the function "Disallow cancellations".This function must be deactivated!+2 moredata-nonce="cf716d3210"