
Zarinpal Gateway Security & Risk Analysis
wordpress.org/plugins/zarinpal-woocommerce-payment-gatewayپرداخت اینترنتی وجه به وسیله درگاه پرداخت واسطه زرین پال
Is Zarinpal Gateway Safe to Use in 2026?
Generally Safe
Score 97/100Zarinpal Gateway has a strong security track record. Known vulnerabilities have been patched promptly.
The zarinpal-woocommerce-payment-gateway plugin, version 5.0.17, exhibits several positive security practices, including the exclusive use of prepared statements for SQL queries and a reasonable percentage of properly escaped output. The absence of identified critical or high severity taint flows is also a good sign. However, the plugin does present some areas of concern. The presence of 7 AJAX handlers, even with all currently protected by authentication, represents a notable attack surface. The file operation and external HTTP requests, while not inherently problematic, warrant attention during further review to ensure they are handled securely. Furthermore, the plugin has a history of known vulnerabilities, specifically one high severity issue related to Improper Access Control. While this vulnerability is currently unpatched, its past occurrence suggests a potential recurring weakness in access control mechanisms. The last recorded vulnerability date also seems to be in the future, which is unusual and requires investigation.
Key Concerns
- Past high severity vulnerability (Improper Access Control)
- 7 AJAX handlers represent a notable attack surface
- One file operation found
- Four external HTTP requests found
- Unusual future date for last vulnerability
Zarinpal Gateway Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Zarinpal Gateway for WooCommerce <= 5.0.16 - Improper Access Control to Payment Status Update
Zarinpal Gateway Code Analysis
Output Escaping
Data Flow Analysis
Zarinpal Gateway Attack Surface
AJAX Handlers 7
WordPress Hooks 25
Maintenance & Trust
Zarinpal Gateway Maintenance & Trust
Maintenance Signals
Community Trust
Zarinpal Gateway Alternatives
ووکامرس فارسی
persian-woocommerce
بسته ووکامرس فارسی به راحتی سیستم فروشگاه ساز ووکامرس را فارسی می کند و امکانات جدید متناسب با ایران را به ووکامرس اضافه میکند.
پارسی دیت – Parsi Date
wp-parsidate
Persian date support for WordPress
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
PayPing Gateway For Woocommerce
woo-payping-gateway
افزونه درگاه پرداخت پیپینگ برای ووکامرس
IranDargah Payment Gateway for Woocommerce
irandargah-payment-gateway-for-woocommerce
پرداخت اینترنتی وجه به وسیله درگاه پرداخت ایران درگاه برای افزونه ووکامرس
Zarinpal Gateway Developer Profile
1 plugin · 60K total installs
How We Detect Zarinpal Gateway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zarinpal-woocommerce-payment-gateway/assets/images/logo.svg/wp-content/plugins/zarinpal-woocommerce-payment-gateway/assets/css/cart.csszarinpal-woocommerce-payment-gateway/assets/css/cart.css?ver=zarinpal-woocommerce-payment-gateway/assets/js/zarinpal.js?ver=HTML / DOM Fingerprints
wc-zpal-gateway-link<!-- zarinpal payment gateway --><!-- Sandbox Mode Active -->data-gateway-id="WC_ZPal"data-merchant-codedata-sandboxwindow.zarinpal_payment_gateway_paramsvar wc_zarinpal_params/wp-json/wc-zarinpal/v1/get-payment-url