WC Total Web Solutions Gateway Security & Risk Analysis

wordpress.org/plugins/woocommerce-total-web-solutions-gateway

TWS payment gateway for Woocommerce.

10 active installs v2.3.2 PHP + WP 3.3+ Updated Unknown
accept-payments-on-woocommerceuk-payment-gatewaywoocommerce-card-paymentswoocommerce-card-processingwoocommerce-payment-gateway
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WC Total Web Solutions Gateway Safe to Use in 2026?

Generally Safe

Score 100/100

WC Total Web Solutions Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of "woocommerce-total-web-solutions-gateway" v2.3.2 reveals a plugin with a seemingly small attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which reduces the potential entry points for attackers. The plugin also demonstrates good practices in its handling of SQL queries, with 100% using prepared statements, and no dangerous functions were detected. However, significant concerns arise from the taint analysis and output escaping. Four flows with unsanitized paths were identified, and while no critical or high severity issues were flagged in taint analysis, the presence of unsanitized paths warrants caution as it could indicate potential injection vulnerabilities. Furthermore, only 19% of output escaping was proper, suggesting a risk of cross-site scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks on any potential entry points (though none were explicitly found in the static scan, the lack of checks is a systemic weakness) is a major concern for authentication and authorization. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. Overall, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the identified unsanitized paths and poor output escaping, coupled with a lack of security checks, present a notable risk.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Low percentage of properly escaped output
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

WC Total Web Solutions Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WC Total Web Solutions Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

19% escaped16 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
response_handler (gateway-totalweb.php:518)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WC Total Web Solutions Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwoocommerce_receipt_totalwebgateway-totalweb.php:62
filterwoocommerce_after_order_notesgateway-totalweb.php:65
actionwoocommerce_checkout_update_order_metagateway-totalweb.php:66
actioninitgateway-totalweb.php:71
actionwoocommerce_api_wc_gateway_totalwebgateway-totalweb.php:78
actionplugins_loadedindex.php:12
filterwoocommerce_payment_gatewaysindex.php:39
Maintenance & Trust

WC Total Web Solutions Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WC Total Web Solutions Gateway Developer Profile

Total Web Solutions

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WC Total Web Solutions Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-total-web-solutions-gateway/images/SupportedCardsMain.png
Version Parameters
woocommerce-total-web-solutions-gateway/includes/authorize-net.php?ver=woocommerce-total-web-solutions-gateway/gateway-totalweb.php?ver=

HTML / DOM Fingerprints

Data Attributes
name="tws_storecard"
REST Endpoints
/wc-api/WC_Gateway_Totalweb
FAQ

Frequently Asked Questions about WC Total Web Solutions Gateway