
WooCommerce PayPal Here Payment Gateway Security & Risk Analysis
wordpress.org/plugins/woocommerce-paypal-here-gatewayAccept payment in-person using PayPal Here as a point-of-sale system.
Is WooCommerce PayPal Here Payment Gateway Safe to Use in 2026?
Generally Safe
Score 85/100WooCommerce PayPal Here Payment Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The WooCommerce PayPal Here Gateway plugin v1.1.3 demonstrates a generally strong security posture. The static analysis reveals a remarkably small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authorization. This indicates a conscious effort by the developers to limit potential entry points for attackers. Furthermore, the code shows good practices regarding SQL queries, all utilizing prepared statements, and a high percentage of output being properly escaped, mitigating common cross-site scripting vulnerabilities. The presence of nonce and capability checks also contributes positively to its security. However, one flow with an unsanitized path was identified in the taint analysis. While this did not reach a critical or high severity, it represents a potential weakness that warrants investigation as it could lead to unexpected behavior or vulnerabilities if exploited, especially if related to file operations or user input. The plugin's vulnerability history is exceptionally clean, with no recorded CVEs, which is a significant strength and suggests mature development and testing practices. This lack of past vulnerabilities, coupled with the current code's robust protections, paints a picture of a well-maintained plugin. The primary concern stems from the single identified taint flow with an unsanitized path, which, despite its current low severity, is the only detected potential weakness in an otherwise secure codebase. The bundled TCPDF library, while not explicitly flagged as outdated, is a potential area for future concern if it is not actively maintained and updated by its upstream maintainers.
Key Concerns
- Flow with unsanitized path identified
- Bundled library (TCPDF) may become outdated
WooCommerce PayPal Here Payment Gateway Security Vulnerabilities
WooCommerce PayPal Here Payment Gateway Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WooCommerce PayPal Here Payment Gateway Attack Surface
WordPress Hooks 11
Maintenance & Trust
WooCommerce PayPal Here Payment Gateway Maintenance & Trust
Maintenance Signals
Community Trust
WooCommerce PayPal Here Payment Gateway Alternatives
2C2P Redirect API for WooCommerce
2c2p-redirect-api-for-woocommerce
Accept Payment (Credit/Debit Cards, Alipay, Alternative/Cash Payments) on your WooCommerce webstore.
Interface for Geniki Taxydromiki API v2 and Woo
interface-for-geniki-taxydromiki-and-woo
Interface for Geniki Taxydromiki API v2 and Woocommerce.
Awesome for WC
awesome-wc
Customize every aspect of your WooCommerce store.
Extended Setup for WooCommerce – Customize your eCommerce
extended-setup-for-woocommerce
WooCommerce Extended Setup is a powerful customizer for WooCommerce that helps you customize with no code.
WooDPD
woodpd
Wordpress plugin for WooCommerce and DPD, with cart button widget.
WooCommerce PayPal Here Payment Gateway Developer Profile
36 plugins · 4.7M total installs
How We Detect WooCommerce PayPal Here Payment Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-paypal-here-gateway/assets/css/admin-style.css/wp-content/plugins/woocommerce-paypal-here-gateway/assets/css/frontend-style.css/wp-content/plugins/woocommerce-paypal-here-gateway/assets/js/admin-script.jswoocommerce-paypal-here-gateway/assets/css/admin-style.css?ver=woocommerce-paypal-here-gateway/assets/css/frontend-style.css?ver=woocommerce-paypal-here-gateway/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
wc-paypal-here-gateway-settingsdata-gateway-id="paypal_here"window.wc_paypal_here_params