
Carta Online Security & Risk Analysis
wordpress.org/plugins/carta-onlineUse the Carta Online WordPress plugin to embed your offerings on your website.
Is Carta Online Safe to Use in 2026?
Mostly Safe
Score 78/100Carta Online is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "carta-online" plugin version 2.15.0 presents a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices. There are no dangerous function calls, all SQL queries are prepared, and a significant majority of output is properly escaped. The plugin also demonstrates good security hygiene by implementing nonce and capability checks on its entry points and avoiding the bundling of external libraries.
However, several concerns warrant attention. The taint analysis indicates that all six analyzed flows have unsanitized paths, although thankfully these are not categorized as critical or high severity. More significantly, the vulnerability history shows one known medium severity CVE which remains unpatched, specifically related to Cross-site Scripting. The last recorded vulnerability date suggests a potential for recurring issues in this area. The plugin also makes two external HTTP requests, which could be a vector for supply chain attacks or information leakage if not handled with extreme care.
In conclusion, while "carta-online" exhibits commendable secure coding practices like prepared statements and output escaping, the presence of an unpatched medium CVE and the taint analysis showing unsanitized paths are significant weaknesses. The past vulnerability type (XSS) and the unpatched status necessitate immediate attention to mitigate potential risks.
Key Concerns
- Unpatched CVE (medium severity)
- Unsanitized paths in all taint flows
- External HTTP requests present
Carta Online Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Carta Online <= 2.13.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
Carta Online Release Timeline
Carta Online Code Analysis
Output Escaping
Data Flow Analysis
Carta Online Attack Surface
AJAX Handlers 2
Shortcodes 9
WordPress Hooks 22
Maintenance & Trust
Carta Online Maintenance & Trust
Maintenance Signals
Community Trust
Carta Online Alternatives
Virtuaria PagBank / PagSeguro para Woocommerce
virtuaria-pagseguro
Crédito, Pix e Boleto na sua loja virtual. Mais segurança, menos chargebacks com 3DS. Descontos nas taxas do PagBank.
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
woo-rede
Payment Gateway for Rede Itaú for WooCommerce - PIX, Credit Card and Debit Cards.
ilGhera Carta Docente for WooCommerce
wc-carta-docente
Abilita in WooCommerce il pagamento con Carta del Docente.
iPag Pagamentos Digitais
ipag-woocommerce
Facilite pagamentos online com segurança e rapidez, integrando sua loja ao nosso gateway e PSP.
Virtuaria Rede ( Itaú ) Pagamentos
virtuaria-eredeitau
Pagamentos via Pix e Cartão de Crédito na sua loja virtual com a confiabilidade da Rede / Itaú diretamente em seu WooCommerce.
Carta Online Developer Profile
1 plugin · 40 total installs
How We Detect Carta Online
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/carta-online/css/style.css/wp-content/plugins/carta-online/images/admin_menu_icon.pngcarta-online/css/style.css?ver=