
Zibal Payment Gateway for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/zibal-payment-gateway-for-contact-form7با نصب این پلاگین می توانید از خدمات درگاه پرداخت زیبال برروی افزونه فرم تماس ۷ استفاده کنید!
Is Zibal Payment Gateway for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100Zibal Payment Gateway for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zibal-payment-gateway-for-contact-form7" plugin version 1.0 exhibits a generally positive security posture with no known vulnerabilities or critical security flaws detected in the static analysis. The plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and performs a reasonable amount of output escaping, with 64% of outputs being properly handled. It also correctly limits its attack surface to a single shortcode and has limited capability checks for its entry points.
However, there are a few areas of concern. The presence of one taint flow with an unsanitized path, rated as high severity, is a significant risk that could potentially lead to vulnerabilities if exploited. While there are no external HTTP requests or file operations flagged, and no dangerous functions are used, the lack of any nonce checks across all entry points is a notable weakness. This could make certain operations susceptible to Cross-Site Request Forgery (CSRF) attacks, especially if the shortcode or any implicit actions it triggers are sensitive.
In conclusion, the plugin's strength lies in its responsible handling of database interactions and lack of historical vulnerabilities. The main weaknesses are the high-severity unsanitized taint flow and the absence of nonce checks. Addressing these specific issues would significantly improve the plugin's overall security. The plugin's limited entry points and controlled code execution pathways are positive factors, but the identified taint flow and lack of CSRF protection warrant attention.
Key Concerns
- High severity unsanitized taint flow
- 0 Nonce checks on entry points
- 36% of outputs not properly escaped
Zibal Payment Gateway for Contact Form 7 Security Vulnerabilities
Zibal Payment Gateway for Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Zibal Payment Gateway for Contact Form 7 Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Zibal Payment Gateway for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Zibal Payment Gateway for Contact Form 7 Alternatives
Gateway zibal for Woocommerce
zibal-payment-gateway-for-woocommerce
با نصب این پلاگین می توانید از خدمات درگاه پرداخت واسط و مستقیم و یا اختصاصی زیبال برروی فروشگاه ساز ووکامرس استفاده کنید
Zibal Payment Gateway for Gravity Forms
zibal-payment-gateway-for-gravity-forms
با نصب این پلاگین می توانید از خدمات درگاه پرداخت واسط و مستقیم و یا اختصاصی زیبال برروی افزونه گرویتی فرم استفاده کنید!
Zibal Payment Gateway for Easy Digital Downloads
zibal-payment-gateway-for-easy-digital-downloads
با نصب این پلاگین می توانید از خدمات درگاه پرداخت واسط و مستقیم و یا اختصاصی زیبال برروی اسکریپت فروش فایل easy digital downloads استفاده کنید!
Zibal Payment Gateway for Learnpress
zibal-payment-learnpress
با نصب این پلاگین می توانید از خدمات درگاه پرداخت واسط و مستقیم و یا اختصاصی زیبال برروی افزونه لرن پرس استفاده کنید!
Accept 2Checkout Payments Using Contact Form 7
accept-2checkout-payments-using-contact-form-7
The 2Checkout Payment system provides a secure, simple means of authorizing credit and debit card transactions from your website.
Zibal Payment Gateway for Contact Form 7 Developer Profile
5 plugins · 7K total installs
How We Detect Zibal Payment Gateway for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zibal-payment-gateway-for-contact-form7/style.csszibal-payment-gateway-for-contact-form7/style.css?ver=HTML / DOM Fingerprints
vipbodymrbox2data-cf7pp-merchantdata-cf7pp-amountdata-cf7pp-descriptiondata-cf7pp-namedata-cf7pp-emaildata-cf7pp-phone+1 morewindow.ZibalCF7<div style="border:#CCC 1px solid; width:90%;"><div class="mrbox2"><h3><span><html><head>