
WpYar EDD Saman Bank Gateway Security & Risk Analysis
wordpress.org/plugins/wpyar-edd-saman-bank-gatewayA plugin for adding Saman Bank payment gateway to plugin edd
Is WpYar EDD Saman Bank Gateway Safe to Use in 2026?
Generally Safe
Score 85/100WpYar EDD Saman Bank Gateway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpyar-edd-saman-bank-gateway plugin version 1.1 presents a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it exhibits strong output escaping practices with 89% of outputs being properly sanitized, and it does not perform file operations or external HTTP requests. The absence of any known vulnerabilities in its history is also a positive indicator.
However, significant concerns arise from the static analysis of its code. The plugin uses raw SQL queries without any prepared statements, which is a major security risk for SQL injection vulnerabilities. Despite having a low total number of flows analyzed, two flows were identified with unsanitized paths, and these were flagged as high severity taint flows. The complete lack of nonce checks and capability checks across all identified entry points (even though there are none) is a general best practice that is not being followed, indicating a potential for privilege escalation or unauthorized actions if new entry points were to be introduced without proper security measures.
In conclusion, while the plugin benefits from a limited attack surface and good output escaping, the presence of raw SQL queries and high-severity unsanitized taint flows are critical vulnerabilities that require immediate attention. The lack of recorded vulnerability history is a strength, but it cannot negate the direct risks identified in the code itself. The plugin's security can be significantly improved by addressing the SQL injection risks and the identified taint flows.
Key Concerns
- SQL queries without prepared statements
- High severity taint flows (2)
- No nonce checks implemented
- No capability checks implemented
WpYar EDD Saman Bank Gateway Security Vulnerabilities
WpYar EDD Saman Bank Gateway Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WpYar EDD Saman Bank Gateway Attack Surface
WordPress Hooks 10
Maintenance & Trust
WpYar EDD Saman Bank Gateway Maintenance & Trust
Maintenance Signals
Community Trust
WpYar EDD Saman Bank Gateway Alternatives
Bank Saman EDD gateway
bank-saman-edd-gateway
Add Bank Saman payment gateway to easy digital downloads transactions
Bank Melli EDD gateway
bank-melli-edd-gateway
This plugin will add Bank Melli Iran and Shaparak Electronic Network gateway to EDD plugin.
Bank mellat EDD gateway
bank-mellat-edd-gateway
This plugin will add Bank Mellat and Shaparak Electronic Network gateway to EDD plugin + sms افزونه بانک ملت برای افزونه فروش فایل EDD
Bank Parsian EDD gateway
bank-saderat-edd-gateway
This plugin will add Bank Parsian Iran and Shaparak Electronic Network gateway to EDD plugin
Bulk Edit Posts and Products in Spreadsheet
wp-sheet-editor-bulk-spreadsheet-editor-for-posts-and-pages
Modern Bulk Editor for Posts and Pages, create and edit hundreds of posts at once in a spreadsheet inside wp-admin. Search and quick edits.
WpYar EDD Saman Bank Gateway Developer Profile
1 plugin · 30 total installs
How We Detect WpYar EDD Saman Bank Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpyar-edd-saman-bank-gateway/inc/template/css/style.csswpyar-edd-saman-bank-gateway/inc/template/css/style.css?ver=1.1HTML / DOM Fingerprints
<!-- START ADD LANG --><!-- END ADD LANG --><!-- START ADD GATEWAY SETTING --><!-- END ADD GATEWAY SETTING -->+1 moreid="checkout_confirmation"