WpYar EDD Saman Bank Gateway Security & Risk Analysis

wordpress.org/plugins/wpyar-edd-saman-bank-gateway

A plugin for adding Saman Bank payment gateway to plugin edd

30 active installs v1.1 PHP + WP 4.6+ Updated Mar 2, 2017
bank-samaneasy-digital-downloadsedd-gatewayspersian-bankssaman
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WpYar EDD Saman Bank Gateway Safe to Use in 2026?

Generally Safe

Score 85/100

WpYar EDD Saman Bank Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The wpyar-edd-saman-bank-gateway plugin version 1.1 presents a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it exhibits strong output escaping practices with 89% of outputs being properly sanitized, and it does not perform file operations or external HTTP requests. The absence of any known vulnerabilities in its history is also a positive indicator.

However, significant concerns arise from the static analysis of its code. The plugin uses raw SQL queries without any prepared statements, which is a major security risk for SQL injection vulnerabilities. Despite having a low total number of flows analyzed, two flows were identified with unsanitized paths, and these were flagged as high severity taint flows. The complete lack of nonce checks and capability checks across all identified entry points (even though there are none) is a general best practice that is not being followed, indicating a potential for privilege escalation or unauthorized actions if new entry points were to be introduced without proper security measures.

In conclusion, while the plugin benefits from a limited attack surface and good output escaping, the presence of raw SQL queries and high-severity unsanitized taint flows are critical vulnerabilities that require immediate attention. The lack of recorded vulnerability history is a strength, but it cannot negate the direct risks identified in the code itself. The plugin's security can be significantly improved by addressing the SQL injection risks and the identified taint flows.

Key Concerns

  • SQL queries without prepared statements
  • High severity taint flows (2)
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

WpYar EDD Saman Bank Gateway Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WpYar EDD Saman Bank Gateway Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

89% escaped9 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
saman_bank_verify_edd (inc\core\add-gateway-settings.php:210)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WpYar EDD Saman Bank Gateway Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
filteredd_accepted_payment_iconsinc\core\add-gateway-settings.php:18
filteredd_rial_currency_filter_afterinc\core\add-gateway-settings.php:92
filteredd_saman-bank_cc_forminc\core\add-gateway-settings.php:102
filteredd_settings_sections_gatewaysinc\core\add-gateway-settings.php:112
filteredd_settings_gatewaysinc\core\add-gateway-settings.php:148
actionedd_gateway_saman-bankinc\core\add-gateway-settings.php:206
actioninitinc\core\add-gateway-settings.php:261
filterthe_contentinc\core\add-gateway-settings.php:291
filteredd_payment_gatewaysinc\core\add-gateway-settings.php:302
actionplugins_loadedinc\core\lang.php:4
Maintenance & Trust

WpYar EDD Saman Bank Gateway Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMar 2, 2017
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

WpYar EDD Saman Bank Gateway Developer Profile

Amir Hossein Habibi

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WpYar EDD Saman Bank Gateway

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpyar-edd-saman-bank-gateway/inc/template/css/style.css
Version Parameters
wpyar-edd-saman-bank-gateway/inc/template/css/style.css?ver=1.1

HTML / DOM Fingerprints

HTML Comments
<!-- START ADD LANG --><!-- END ADD LANG --><!-- START ADD GATEWAY SETTING --><!-- END ADD GATEWAY SETTING -->+1 more
Data Attributes
id="checkout_confirmation"
FAQ

Frequently Asked Questions about WpYar EDD Saman Bank Gateway