
Buen Fin Security & Risk Analysis
wordpress.org/plugins/buen-finPlugin para mostrar el precio de los productos a 3, 6, 9, 12 Meses sin Intereses en la pagina individual de productos de WooCommerce, antes del boton …
Is Buen Fin Safe to Use in 2026?
Generally Safe
Score 85/100Buen Fin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'buen-fin' v1.0.2 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the code signals show a lack of dangerous functions and file operations, and importantly, no external HTTP requests are made. However, the analysis does highlight a critical concern: a single SQL query that is not using prepared statements. This is a significant risk as it opens the door to SQL injection vulnerabilities. While the output escaping is reasonably well-handled (79%), the presence of unsanitized SQL remains a notable weakness. The vulnerability history being entirely clear of known CVEs is an excellent indicator of past security diligence or a lack of past targeting. In conclusion, while the plugin benefits from a small attack surface and good practices in other areas, the unqualified SQL query is a serious flaw that requires immediate attention. The lack of vulnerability history is a positive, but it does not negate the risks identified in the current code.
Key Concerns
- SQL query without prepared statements
Buen Fin Security Vulnerabilities
Buen Fin Code Analysis
SQL Query Safety
Output Escaping
Buen Fin Attack Surface
WordPress Hooks 8
Maintenance & Trust
Buen Fin Maintenance & Trust
Maintenance Signals
Community Trust
Buen Fin Alternatives
Clip Transparent Checkout
clip-mexico-payments-for-ecommerce-transparent-checkout
Accept all local Mexican and international card payments with Clip (Credit, Debit, Vale cards, Months without interest, Visa, MC, AMEX, Discover, Dine …
PKT1 Centro de envios
pkt1-centro-de-envios
Calcule tarifas de envio en tiempo real con los principales agentes de paqueteria regionales y mundiales
Banorte Woocommerce
woo-banorte
Integration of banorte bank with woocommerce
COMITI Invoicing Cloud for Ecommerce
efitec-facturacion-for-comiti
CFDI 4.0 invoicing extension for WooCommerce integrated with COMITI’s services.
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Buen Fin Developer Profile
3 plugins · 160 total installs
How We Detect Buen Fin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buen-fin-woo/css/buen-fin-woo-admin.css/wp-content/plugins/buen-fin-woo/js/buen-fin-woo-admin.jsadmin/js/buen-fin-woo-admin.jsbuen-fin-woo-admin.css?ver=buen-fin-woo-admin.js?ver=