Sofortueberweisung Gateway for Woocommerce Security & Risk Analysis

wordpress.org/plugins/woo-sofortuberweisung-gateway

Allows your users to pay over Sofortüberweisung via WooCommerce checkout. Easy, fast and safe. Setup is very easy.

700 active installs v1.3.4 PHP 5.2.4+ WP 4.0+ Updated Oct 25, 2020
gatewayklarnapayment-gatewaysofortueberweisungwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sofortueberweisung Gateway for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Sofortueberweisung Gateway for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "woo-sofortuberweisung-gateway" plugin v1.3.4 presents a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL injection, utilizing prepared statements exclusively, and it has no recorded vulnerability history, suggesting a generally stable codebase. The lack of registered CVEs and its most recent vulnerability being unrecorded further bolster this impression.

However, the static analysis reveals significant areas of concern. The most critical finding is the presence of three unsanitized path flows, indicating potential for directory traversal or unintended file access vulnerabilities. Additionally, the very low percentage of properly escaped output (5%) is a substantial risk, exposing the application to cross-site scripting (XSS) attacks. The absence of any nonce or capability checks across the entire plugin, coupled with the lack of authentication checks on any entry points (though the attack surface is zero), suggests a general disregard for input validation and authorization mechanisms. While the current attack surface is zero, any future additions without proper checks could be immediately exploitable.

In conclusion, while the plugin's SQL handling and lack of historical vulnerabilities are strong points, the identified unsanitized paths and pervasive lack of output escaping and authorization checks introduce critical security weaknesses. The potential for XSS and file access vulnerabilities, combined with a lack of fundamental security checks, means this plugin requires immediate attention despite its clean history.

Key Concerns

  • Unsanitized path flows found
  • Very low output escaping percentage
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Sofortueberweisung Gateway for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sofortueberweisung Gateway for Woocommerce Release Timeline

v1.3.4Current
v1.3.3
v1.2.3
v1.2.2
v1.2.1
v1.2
v1.1
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Sofortueberweisung Gateway for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
7
External Requests
1
Bundled Libraries
0

Output Escaping

5% escaped21 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
__construct (woo-sofortuberweisung-gateway.php:485)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sofortueberweisung Gateway for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
filterwoocommerce_payment_gatewayswoo-sofortuberweisung-gateway.php:26
actionplugins_loadedwoo-sofortuberweisung-gateway.php:32
actionadmin_noticeswoo-sofortuberweisung-gateway.php:41
actionplugins_loadedwoo-sofortuberweisung-gateway.php:58
actionwoocommerce_email_before_order_tablewoo-sofortuberweisung-gateway.php:116
actionadmin_print_footer_scriptswoo-sofortuberweisung-gateway.php:119
filterwoocommerce_gateway_iconwoo-sofortuberweisung-gateway.php:121
actionwoocommerce_thankyouwoo-sofortuberweisung-gateway.php:487
Maintenance & Trust

Sofortueberweisung Gateway for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 25, 2020
PHP min version5.2.4
Downloads14K

Community Trust

Rating100/100
Number of ratings7
Active installs700
Developer Profile

Sofortueberweisung Gateway for Woocommerce Developer Profile

mlfactory

8 plugins · 21K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
318 days
View full developer profile
Detection Fingerprints

How We Detect Sofortueberweisung Gateway for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-sofortuberweisung-gateway/core/klarna.svg/wp-content/plugins/woo-sofortuberweisung-gateway/core/sofort-logo.png
Version Parameters
woo-sofortuberweisung-gateway/woo-sofortuberweisung-gateway.php?ver=woo-sofortuberweisung-gateway/sofort/core/sofortLibSofortueberweisung.inc.php?ver=woo-sofortuberweisung-gateway/sofort/core/sofortLibNotification.inc.php?ver=woo-sofortuberweisung-gateway/sofort/core/sofortLibTransactionData.inc.php?ver=

HTML / DOM Fingerprints

CSS Classes
notice-info
HTML Comments
VERY IMPORTANTIt was detected that you are using the plugin Germanized for WooCommerce.You have activated the function "Disallow cancellations".This function must be deactivated!+2 more
Data Attributes
data-nonce="cf716d3210"
FAQ

Frequently Asked Questions about Sofortueberweisung Gateway for Woocommerce