
Eway Payments for Woo Security & Risk Analysis
wordpress.org/plugins/woocommerce-gateway-ewayThis is the official WooCommerce extension to take credit card and subscription payments directly on your store with Eway.
Is Eway Payments for Woo Safe to Use in 2026?
Generally Safe
Score 100/100Eway Payments for Woo has a strong security track record. Known vulnerabilities have been patched promptly.
The "woocommerce-gateway-eway" plugin version 3.9.2 exhibits a generally strong security posture, with no critical or high-severity vulnerabilities identified in the static and taint analyses. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The absence of dangerous functions, file operations, and direct external HTTP requests that are not handled through secure means also contributes positively to its security. Furthermore, the presence of nonce and capability checks on its identified entry points (AJAX handlers) is a significant strength, preventing common unauthorized access vulnerabilities.
However, a previous medium-severity vulnerability related to 'Authorization Bypass Through User-Controlled Key' in early 2023 warrants attention. While this vulnerability is no longer present or patched, it suggests a historical pattern of potential authorization weaknesses. The presence of 4 AJAX handlers, while all appearing to have authentication checks based on the provided data, still represents an attack surface. The two external HTTP requests, though not explicitly detailed as risky, could pose a risk if not properly secured or validated on the receiving end. The fact that all known CVEs are patched is commendable, but the nature of past vulnerabilities should be a reminder for ongoing vigilance.
In conclusion, the plugin is well-developed from a security perspective in its current version, with robust coding practices evident. The past medium-severity vulnerability is the primary area of concern and a reminder of the importance of continuous security auditing. The current static and taint analysis results are positive, indicating minimal immediate risk. However, the historical vulnerability pattern suggests that diligent review of any future updates for similar authorization-related issues would be prudent.
Key Concerns
- Past medium vulnerability: Authorization Bypass
- External HTTP requests exist
Eway Payments for Woo Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WooCommerce Eway Gateway <= 3.5.0 - Insecure Direct Object Reference
Eway Payments for Woo Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Eway Payments for Woo Attack Surface
AJAX Handlers 4
WordPress Hooks 23
Maintenance & Trust
Eway Payments for Woo Maintenance & Trust
Maintenance Signals
Community Trust
Eway Payments for Woo Alternatives
Asaas Gateway for WooCommerce
woo-asaas
Take transparent credit card and bank ticket payment checkouts on your store using Asaas.
PayPlug for WooCommerce (Official)
payplug
PlayPlug is a French payment solution allowing small and medium e-commerce companies to accept online payments from Visa, MasterCard and CB cards.
Gestpay for WooCommerce
gestpay-for-woocommerce
Axerve Free Plugin for Woocommerce extends WooCommerce providing the payment gateway Axerve.
Payment gateway via Teya SecurePay for WooCommerce
payment-gateway-via-borgun-for-woocommerce
Take payments in your WooCommerce store using the Teya SecurePay Gateway
PayPlus Payment Gateway
payplus-payment-gateway
Accept credit/debit card payments or other methods such as bit, Apple Pay, Google Pay in one page. Create digitally signed invoices & much more!
Eway Payments for Woo Developer Profile
36 plugins · 4.7M total installs
How We Detect Eway Payments for Woo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-gateway-eway/assets/js/eway-public.js/wp-content/plugins/woocommerce-gateway-eway/assets/js/eway-checkout.js/wp-content/plugins/woocommerce-gateway-eway/assets/css/eway-public.css/wp-content/plugins/woocommerce-gateway-eway/assets/css/eway-checkout.css/wp-content/plugins/woocommerce-gateway-eway/includes/class-wc-gateway-eway-blocks-support.php/wp-content/plugins/woocommerce-gateway-eway/includes/class-wc-gateway-eway.php/wp-content/plugins/woocommerce-gateway-eway/includes/class-wc-gateway-eway-error-codes.php/wp-content/plugins/woocommerce-gateway-eway/includes/class-wc-gateway-eway-privacy.php+4 more/wp-content/plugins/woocommerce-gateway-eway/assets/js/eway-public.js/wp-content/plugins/woocommerce-gateway-eway/assets/js/eway-checkout.js/wp-content/plugins/woocommerce-gateway-eway/assets/js/eway-public.js?ver=/wp-content/plugins/woocommerce-gateway-eway/assets/js/eway-checkout.js?ver=/wp-content/plugins/woocommerce-gateway-eway/assets/css/eway-public.css?ver=/wp-content/plugins/woocommerce-gateway-eway/assets/css/eway-checkout.css?ver=HTML / DOM Fingerprints
eway-checkout-fieldseway-card-numbereway-card-expiryeway-card-cvneway-card-nameeway-pay-now-buttoneway-payment-buttoneway-secure-fields-wrapper+2 more<!-- eway_customer_id --><!-- eway_transaction_id --><!-- eway_access_code --><!-- Eway Payment Gateway -->+3 moredata-eway-public-keydata-eway-customer-iddata-eway-testmodedata-eway-countrydata-eway-form-iddata-eway-gateway-url+6 moreeway_paramseway_public_paramseway_checkout_paramseway_scriptseway_gatewayeway_payment_gateway_params+13 more/wp-json/eway/v1/payment_gateway/wp-json/eway/v1/process_payment/wp-json/eway/v1/token_payment[eway_payment_form][eway_gateway_details][eway_transaction_status]