Boleto Pag Seguro Direto Security & Risk Analysis

wordpress.org/plugins/boleto-pag-seguro-direto

Gera o boleto do Pag Seguro sem digitação da senha. Carnê de boletos sequenciais. A CADA ATUALIZAÇÃO veja a instruções na página de <a href="plugins.php?page=BoletoPagSeguroDireto_PluginSettings"> CONFIGURAÇÕES </a>. <a href="https://entregador.click/wordpress-works/form-dados-do-boleto/" target="_blank" rel="noopener noreferrer">. Gere um boleto de doação, efetue o pagamento para receber suporte.</a> <a href="https://entregador.click/wordpress-works/" target="_blank" rel="noopener noreferrer">. Conheça a versão Pro.</a>

60 active installs v1.2 PHP + WP 3.5+ Updated Oct 11, 2020
boletodoacaopag-seguropagsegurorecebimentos-de-doacoes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Boleto Pag Seguro Direto Safe to Use in 2026?

Generally Safe

Score 85/100

Boleto Pag Seguro Direto has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "boleto-pag-seguro-direto" v1.2 plugin exhibits a generally good security posture due to its complete lack of known vulnerabilities and a seemingly low attack surface based on the static analysis. The absence of CVEs and its history of no recorded vulnerabilities are strong indicators of diligent security practices in past development. Furthermore, the use of prepared statements for all SQL queries is an excellent practice that mitigates common SQL injection risks. The plugin also implements nonce and capability checks, demonstrating an awareness of WordPress security mechanisms.

However, a significant concern arises from the output escaping. With 17% of outputs properly escaped, a substantial portion (83%) are likely unescaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data rendered by the plugin might not be properly sanitized before being displayed in the browser. The taint analysis also revealed that all analyzed flows had unsanitized paths, though thankfully without critical or high severity findings. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure they are handled in a secure manner, especially in conjunction with the poor output escaping.

Key Concerns

  • High percentage of unescaped output
  • Taint analysis shows unsanitized paths
Vulnerabilities
None known

Boleto Pag Seguro Direto Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Boleto Pag Seguro Direto Release Timeline

v1.2Current
v1.1
v1.0
v0.9
Code Analysis
Analyzed Apr 16, 2026

Boleto Pag Seguro Direto Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
117
24 escaped
Nonce Checks
2
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared9 total queries

Output Escaping

17% escaped141 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
<dados-do-boleto> (boleto/pages/dados-do-boleto.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Boleto Pag Seguro Direto Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initBoletoPagSeguroDireto_OptionsManager.php:225
actioninitBoletoPagSeguroDireto_Plugin.php:105
actionadmin_menuBoletoPagSeguroDireto_Plugin.php:120
actionwp_footerBoletoPagSeguroDireto_ShortCodeScriptLoader.php:31
actionadmin_noticesboleto-pag-seguro-direto.php:88
actionplugins_loadedboleto-pag-seguro-direto.php:148
Maintenance & Trust

Boleto Pag Seguro Direto Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedOct 11, 2020
PHP min version
Downloads20K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Boleto Pag Seguro Direto Developer Profile

clodoaldoevangelista

6 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Boleto Pag Seguro Direto

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Boleto Pag Seguro Direto