Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Security & Risk Analysis

wordpress.org/plugins/casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang

Kết nối các ngân hàng Việt Nam vào Woocommerce, tự động xác nhận đơn hàng đã thanh toán. Hỗ trợ hơn 10 ngân hàng : VietinBank, OCB, Vietcombank, Techc …

300 active installs v4.1.0 PHP + WP + Updated Aug 28, 2024
gatewayket-noi-ngan-hangpayment-gatewayvietcombankwoocommerce
92
A · Safe
CVEs total1
Unpatched0
Last CVEOct 3, 2022
Safety Verdict

Is Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Safe to Use in 2026?

Generally Safe

Score 92/100

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 3, 2022Updated 1yr ago
Risk Assessment

The plugin "casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang" v4.1.0 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and only one nonce check, significant concerns arise from its attack surface and output escaping. The presence of four AJAX handlers without authentication checks presents a substantial risk, as these can be accessed and potentially exploited by unauthenticated users.

The static analysis reveals a worrying trend in taint analysis, with three out of three flows showing unsanitized paths. Although no critical or high severity taint flows were identified, this indicates a potential for various vulnerabilities if the data within these flows is not properly handled. The high rate of improperly escaped output (44%) further exacerbates this risk, suggesting a strong possibility of Cross-Site Scripting (XSS) vulnerabilities.

Historically, the plugin has a known CVE, which was a medium severity Cross-site Scripting vulnerability. The fact that this vulnerability is currently patched is positive, but the pattern of past XSS vulnerabilities, coupled with the current high percentage of unescaped output, suggests that this could be a recurring issue. Overall, the plugin has strengths in its SQL handling but is significantly weakened by its unprotected AJAX endpoints and inadequate output sanitization, making it a moderate risk.

Key Concerns

  • AJAX handlers without authentication checks
  • Unsanitized paths in taint analysis
  • High percentage of improperly escaped output
  • Known CVE (medium severity XSS) in vulnerability history
Vulnerabilities
1

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-edf0760c-356a-4c55-9ccc-9f086dae12b6-casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hangmedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng <= 2.8.6 - Authenticated (Admin+) Cross-Site Scripting

Oct 3, 2022 Patched in 2.8.7 (477d)
Code Analysis
Analyzed Mar 16, 2026

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
55 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
10
Bundled Libraries
0

Output Escaping

56% escaped99 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
save_settings (inc\class-casso-admin-page.php:50)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

noprivwp_ajax_fetch_order_status_cassowc-gateway-casso.php:162
authwp_ajax_fetch_order_status_cassowc-gateway-casso.php:163
noprivwp_ajax_fetch_sync_order_cassowc-gateway-casso.php:164
authwp_ajax_fetch_sync_order_cassowc-gateway-casso.php:165
WordPress Hooks 9
actionwoocommerce_email_before_order_tableinc\banks\class-casso-base.php:64
actionadmin_menuinc\class-casso-admin-page.php:44
actionplugins_loadedwc-gateway-casso.php:98
actionwoocommerce_blocks_loadedwc-gateway-casso.php:99
actioninitwc-gateway-casso.php:101
filterwc_order_statuseswc-gateway-casso.php:143
actionadmin_noticeswc-gateway-casso.php:168
filterwoocommerce_payment_gatewayswc-gateway-casso.php:294
actionwoocommerce_blocks_payment_method_type_registrationwc-gateway-casso.php:361
Maintenance & Trust

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 28, 2024
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng Developer Profile

diepmagik

2 plugins · 4K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
477 days
View full developer profile
Detection Fingerprints

How We Detect Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/casso-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang/assets/css/style.css
Version Parameters
/assets/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Casso – Tự động xác nhận thanh toán chuyển khoản ngân hàng