
Boleto Cora para WooCommerce © Security & Risk Analysis
wordpress.org/plugins/boleto-coraEmita boletos 100% grátis agora mesmo! Conta grátis, TED grátis Cartão VISA sem anuidade!
Is Boleto Cora para WooCommerce © Safe to Use in 2026?
Generally Safe
Score 85/100Boleto Cora para WooCommerce © has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'boleto-cora' v1.1.8 plugin exhibits a generally strong security posture in terms of its attack surface and vulnerability history. The absence of any recorded CVEs and a clean vulnerability history suggest a commitment to security by the developers or a lack of past exploitation. Furthermore, the plugin demonstrates good practices in SQL query handling by exclusively using prepared statements and has no recorded vulnerabilities. However, the static analysis does reveal some areas for concern. A significant portion of output is not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is present in these outputs. While the taint analysis found no critical or high-severity issues, it did identify two flows with unsanitized paths, which could potentially be exploited if these paths involve user input or sensitive operations. The lack of capability checks and nonce checks on potential entry points, though currently zero, is a concerning oversight that could become a vulnerability if new entry points are introduced without proper authorization checks. The presence of file operations and external HTTP requests, while not inherently insecure, necessitates careful review to ensure these are handled securely and do not expose the site to additional risks.
Key Concerns
- High percentage of unescaped output
- Flows with unsanitized paths detected
- No capability checks present
- No nonce checks present
Boleto Cora para WooCommerce © Security Vulnerabilities
Boleto Cora para WooCommerce © Code Analysis
Output Escaping
Data Flow Analysis
Boleto Cora para WooCommerce © Attack Surface
WordPress Hooks 18
Maintenance & Trust
Boleto Cora para WooCommerce © Maintenance & Trust
Maintenance Signals
Community Trust
Boleto Cora para WooCommerce © Alternatives
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Checkout Field Manager (Checkout Manager) for WooCommerce
woocommerce-checkout-manager
Checkout Field Manager (Checkout Manager) for WooCommerce is the most advanced plugin to customize checkout fields on your WooCommerce checkout page.
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager
flexible-checkout-fields
The best WooCommerce checkout manager. Edit, remove or add checkout fields. Customize WooCommerce checkout with this checkout field customizer.
Direct Checkout for WooCommerce
woocommerce-direct-checkout
Formerly "WooCommerce Direct Checkout". This plugin simplifies the entire WooCommerce checkout process to improve your sales rate.
Brazilian Market on WooCommerce
woocommerce-extra-checkout-fields-for-brazil
Adds Brazilian checkout fields in WooCommerce
Boleto Cora para WooCommerce © Developer Profile
1 plugin · 50 total installs
How We Detect Boleto Cora para WooCommerce ©
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boleto-cora/includes/css/woo-cora-gateway.css/wp-content/plugins/boleto-cora/includes/js/woo-cora-gateway.js/wp-content/plugins/boleto-cora/includes/js/woo-cora-gateway.jscora-woocommerce/includes/css/woo-cora-gateway.css?ver=cora-woocommerce/includes/js/woo-cora-gateway.js?ver=HTML / DOM Fingerprints
wcbcf-addresswoocommerce-infoname="cora_document"wc_cora_gateway_params/wp-json/cora-woocommerce/v1/webhook/<a class="button" href="