Buen Fin Security & Risk Analysis

wordpress.org/plugins/buen-fin

Plugin para mostrar el precio de los productos a 3, 6, 9, 12 Meses sin Intereses en la pagina individual de productos de WooCommerce, antes del boton …

0 active installs v1.0.2 PHP + WP 5.5+ Updated Nov 10, 2022
buen-finmeses-sin-interesesmexicowoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Buen Fin Safe to Use in 2026?

Generally Safe

Score 85/100

Buen Fin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'buen-fin' v1.0.2 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the code signals show a lack of dangerous functions and file operations, and importantly, no external HTTP requests are made. However, the analysis does highlight a critical concern: a single SQL query that is not using prepared statements. This is a significant risk as it opens the door to SQL injection vulnerabilities. While the output escaping is reasonably well-handled (79%), the presence of unsanitized SQL remains a notable weakness. The vulnerability history being entirely clear of known CVEs is an excellent indicator of past security diligence or a lack of past targeting. In conclusion, while the plugin benefits from a small attack surface and good practices in other areas, the unqualified SQL query is a serious flaw that requires immediate attention. The lack of vulnerability history is a positive, but it does not negate the risks identified in the current code.

Key Concerns

  • SQL query without prepared statements
Vulnerabilities
None known

Buen Fin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Buen Fin Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
8
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

79% escaped39 total outputs
Attack Surface

Buen Fin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-buen-fin-woo.php:142
actionadmin_enqueue_scriptsincludes\class-buen-fin-woo.php:157
actionadmin_enqueue_scriptsincludes\class-buen-fin-woo.php:158
filterwoocommerce_get_sections_productsincludes\class-buen-fin-woo.php:161
filterwoocommerce_get_settings_productsincludes\class-buen-fin-woo.php:163
actionwp_enqueue_scriptsincludes\class-buen-fin-woo.php:177
actionwp_enqueue_scriptsincludes\class-buen-fin-woo.php:178
actionwoocommerce_before_add_to_cart_formincludes\class-buen-fin-woo.php:181
Maintenance & Trust

Buen Fin Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 10, 2022
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Buen Fin Developer Profile

Manuel Ramírez Coronel

3 plugins · 160 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buen Fin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buen-fin-woo/css/buen-fin-woo-admin.css/wp-content/plugins/buen-fin-woo/js/buen-fin-woo-admin.js
Script Paths
admin/js/buen-fin-woo-admin.js
Version Parameters
buen-fin-woo-admin.css?ver=buen-fin-woo-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Buen Fin