
Payment Gateway Per Product for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woocommerce-product-paymentsControl WooCommerce payment gateways per product, category, or tag. Show the right payment methods at checkout and increase conversions.
Is Payment Gateway Per Product for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Payment Gateway Per Product for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The WooCommerce Product Payments plugin, version 3.6.5, exhibits a generally strong security posture with a remarkably clean attack surface, reporting zero AJAX handlers, REST API routes, shortcodes, or cron events. This significantly limits potential entry points for attackers. The code analysis also reveals good practices regarding SQL queries, all of which are properly prepared, and a high percentage of output escaping. The presence of nonces and capability checks further bolsters security by verifying user intent and permissions.
However, the use of the dangerous `unserialize` function four times is a significant concern. While not flagged as critical or high in the taint analysis, deserialization vulnerabilities can be severe if input is not strictly controlled. The single external HTTP request, while not inherently risky, warrants attention to ensure its target and data transmission are secure. The vulnerability history, with two medium-severity CVEs related to missing authorization and XSS, indicates a past tendency for these types of issues, even though none are currently unpatched. This suggests a need for continued vigilance in these areas.
In conclusion, the plugin has a robust defense against common attack vectors due to its limited attack surface and good implementation of core WordPress security features. The primary areas for improvement lie in addressing the multiple uses of `unserialize` and ensuring that past vulnerability patterns, particularly around authorization and XSS, are fully mitigated. The plugin's strengths in core security practices are commendable, but the specific risks identified necessitate careful review and potential remediation.
Key Concerns
- Use of unserialize function
- Past medium severity CVEs
- Bundled library (Freemius v1.0)
- Bundled library (Select2)
- One external HTTP request
Payment Gateway Per Product for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Dreamfox Media Payment gateway per Product for Woocommerce <= 3.5.8 - Missing Authorization
Payment gateway per Product for WooCommerce <= 3.2.7 - Reflected Cross-Site Scripting
Payment Gateway Per Product for WooCommerce Release Timeline
Payment Gateway Per Product for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Payment Gateway Per Product for WooCommerce Attack Surface
WordPress Hooks 27
Maintenance & Trust
Payment Gateway Per Product for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Payment Gateway Per Product for WooCommerce Alternatives
Hosted Checkout For WC Stripe
wc-stripe-hosted-checkout
Woocomemerce Supported Stripe Hosted Checkout
YD Gateway 2Checkout for WooCommerce
yd-2checkout-gateway-for-woocommerce
YD Gateway 2Checkout for WooCommerce provides an easy way to take credit card payments on your online store using 2Checkout.
Payment Gateway for PayPal on WooCommerce
woo-paypal-gateway
PayPal, Credit/Debit Cards, Google Pay, Apple Pay, Pay Later, Venmo, SEPA, iDEAL, Mercado Pago, Bancontact & more - by an official PayPal Partner
Stripe Payment Forms by WP Simple Pay – Accept Credit Card Payments + Subscriptions with Stripe
stripe
🤩 Accept Stripe payments and recurring subscriptions on your WordPress using WP Simple Pay, the best Stripe payments plugin! 🚀
Payment Gateway of Stripe for WooCommerce
payment-gateway-stripe-and-woocommerce-integration
Integrate Stripe Payment Gateway in WooCommerce and accept cards, Google Pay, Apple Pay, Klarna, Alipay, and more with seamless, secure checkout.
Payment Gateway Per Product for WooCommerce Developer Profile
6 plugins · 410 total installs
How We Detect Payment Gateway Per Product for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woocommerce-product-payments/css/style.css/wp-content/plugins/woocommerce-product-payments/js/setting.jswoocommerce-product-payments/css/style.css?ver=woocommerce-product-payments/js/setting.js?ver=HTML / DOM Fingerprints
dfm-payment-gateway-per-product-for-woocommerceDO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK.data-product-iddd_settings_data