
Autentify anti fraud for WooCommerce Security & Risk Analysis
wordpress.org/plugins/autentify-anti-fraud-for-woocommerceAUTENTIFY é uma plataforma de prevenção a fraude em tempo real que ajuda comerciantes de todos os tamanhos na tomada de decisão.
Is Autentify anti fraud for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Autentify anti fraud for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'autentify-anti-fraud-for-woocommerce' v2.2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or known CVEs, suggesting a generally stable development history. However, significant concerns arise from the static analysis. The presence of three AJAX handlers without any authentication checks creates a substantial attack surface that is entirely unprotected.
Furthermore, the lack of nonce checks on these AJAX handlers is a critical oversight, as it opens the door to Cross-Site Request Forgery (CSRF) attacks. While no critical taint flows were identified, the high percentage of improperly escaped output (34%) presents a risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also makes external HTTP requests, which, without further analysis, could potentially be exploited if those endpoints are compromised or if the requests themselves are not properly validated.
In conclusion, while the absence of historical vulnerabilities and the use of prepared statements are positive indicators, the unprotected AJAX endpoints and the significant number of unescaped outputs represent immediate and substantial security risks that require urgent attention. The plugin's strengths in SQL handling are overshadowed by weaknesses in input validation and output escaping for its entry points.
Key Concerns
- AJAX handlers without auth checks
- Missing nonce checks on AJAX handlers
- Significant portion of unescaped output
Autentify anti fraud for WooCommerce Security Vulnerabilities
Autentify anti fraud for WooCommerce Release Timeline
Autentify anti fraud for WooCommerce Code Analysis
Output Escaping
Autentify anti fraud for WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
Autentify anti fraud for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Autentify anti fraud for WooCommerce Alternatives
Fraud Prevention For WooCommerce and EDD
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
It will Prevent fake orders and Blacklist fraud customers of your store.
Blacklist Manager – WooCommerce Anti-Fraud & Checkout Verification & Spam Prevention
wc-blacklist-manager
Anti-fraud, checkout verification and spam prevention plugin for WooCommerce and WordPress forms.
FraudLabs Pro for WooCommerce
fraudlabs-pro-for-woocommerce
Fraud prevention plugin for WooCommerce to minimize payment fraud and avoid chargebacks. With the FraudLabs Pro Micro Plan, you can get 500 free fraud …
Anti Fake Orders & IP Blocker
anti-fake-orders-ip-blocker
Protect your WooCommerce store from fake orders by blocking suspicious IPs, emails, and detecting bot checkout activity.
IPQualityScore Fraud Detection
ipqualityscore-fraud-detection
IPQualityScore Fraud Detection and Fraud Prevention Tools identify malicious behavior and fraudulent activity featuring Proxy & VPN Detection & …
Autentify anti fraud for WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect Autentify anti fraud for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autentify-anti-fraud-for-woocommerce/assets/css/autentify.css/wp-content/plugins/autentify-anti-fraud-for-woocommerce/assets/js/autentify.js/wp-content/plugins/autentify-anti-fraud-for-woocommerce/assets/js/autentify.jsautentify-anti-fraud-for-woocommerce/assets/css/autentify.css?ver=autentify-anti-fraud-for-woocommerce/assets/js/autentify.js?ver=HTML / DOM Fingerprints
autentify-api-token-inputautentify-score-badgeAutentify is free software: you can redistribute it and/or modifyAutentify is distributed in the hope that it will be useful,data-autentify-order-iddata-autentify-api-urlautentify_params/wp-json/autentify/v1/webhook/wp-json/autentify/v1/score[autentify_score]