Autentify anti fraud for WooCommerce Security & Risk Analysis

wordpress.org/plugins/autentify-anti-fraud-for-woocommerce

AUTENTIFY é uma plataforma de prevenção a fraude em tempo real que ajuda comerciantes de todos os tamanhos na tomada de decisão.

10 active installs v2.2.1 PHP 5.6+ WP 4.7+ Updated Nov 10, 2024
e-commerce-securityfraud-preventionpayment-protectionrisk-management-pluginwoocommerce-anti-fraud
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Autentify anti fraud for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Autentify anti fraud for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'autentify-anti-fraud-for-woocommerce' v2.2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or known CVEs, suggesting a generally stable development history. However, significant concerns arise from the static analysis. The presence of three AJAX handlers without any authentication checks creates a substantial attack surface that is entirely unprotected.

Furthermore, the lack of nonce checks on these AJAX handlers is a critical oversight, as it opens the door to Cross-Site Request Forgery (CSRF) attacks. While no critical taint flows were identified, the high percentage of improperly escaped output (34%) presents a risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also makes external HTTP requests, which, without further analysis, could potentially be exploited if those endpoints are compromised or if the requests themselves are not properly validated.

In conclusion, while the absence of historical vulnerabilities and the use of prepared statements are positive indicators, the unprotected AJAX endpoints and the significant number of unescaped outputs represent immediate and substantial security risks that require urgent attention. The plugin's strengths in SQL handling are overshadowed by weaknesses in input validation and output escaping for its entry points.

Key Concerns

  • AJAX handlers without auth checks
  • Missing nonce checks on AJAX handlers
  • Significant portion of unescaped output
Vulnerabilities
None known

Autentify anti fraud for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Autentify anti fraud for WooCommerce Release Timeline

v2.2.1Current
v2.2.0
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Autentify anti fraud for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

66% escaped35 total outputs
Attack Surface
3 unprotected

Autentify anti fraud for WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_autentify_autenti_commerce_initiate_analysisapp\actions\autentify_autenti_commerce_actions.php:5
authwp_ajax_autentify_autenti_commerce_update_analysisapp\actions\autentify_autenti_commerce_actions.php:10
authwp_ajax_autentify_autenti_mail_postapp\actions\autentify_autenti_mail_actions.php:66
WordPress Hooks 12
actionwp_async_autentify_autenti_mail_checkapp\actions\autentify_autenti_mail_actions.php:99
actionwoocommerce_order_status_changedapp\actions\autentify_autenti_mail_actions.php:109
actionadmin_enqueue_scriptsapp\models\autentify_plugin.php:35
filterwoocommerce_shop_order_list_table_columnsapp\models\autentify_plugin.php:52
actionwoocommerce_shop_order_list_table_custom_columnapp\models\autentify_plugin.php:63
actionplugins_loadedautentify.php:50
actionbefore_woocommerce_initautentify.php:57
actionadmin_noticesautentify.php:89
actionadmin_noticesautentify.php:91
actionadmin_noticesautentify.php:93
actionadmin_menuincludes\admin-menu.php:2
actionadmin_initincludes\admin-menu.php:6

Scheduled Events 1

wp_async_autentify_autenti_mail_check
Maintenance & Trust

Autentify anti fraud for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 10, 2024
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Autentify anti fraud for WooCommerce Developer Profile

autentify

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Autentify anti fraud for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/autentify-anti-fraud-for-woocommerce/assets/css/autentify.css/wp-content/plugins/autentify-anti-fraud-for-woocommerce/assets/js/autentify.js
Script Paths
/wp-content/plugins/autentify-anti-fraud-for-woocommerce/assets/js/autentify.js
Version Parameters
autentify-anti-fraud-for-woocommerce/assets/css/autentify.css?ver=autentify-anti-fraud-for-woocommerce/assets/js/autentify.js?ver=

HTML / DOM Fingerprints

CSS Classes
autentify-api-token-inputautentify-score-badge
HTML Comments
Autentify is free software: you can redistribute it and/or modifyAutentify is distributed in the hope that it will be useful,
Data Attributes
data-autentify-order-iddata-autentify-api-url
JS Globals
autentify_params
REST Endpoints
/wp-json/autentify/v1/webhook/wp-json/autentify/v1/score
Shortcode Output
[autentify_score]
FAQ

Frequently Asked Questions about Autentify anti fraud for WooCommerce