Cielo WooCommerce – Solução Webservice Security & Risk Analysis

wordpress.org/plugins/cielo-woocommerce

Adds Brazilian payment gateway Cielo to WooCommerce

300 active installs v4.0.14 PHP + WP 3.9+ Updated Aug 10, 2020
cielopayment-gatewaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cielo WooCommerce – Solução Webservice Safe to Use in 2026?

Generally Safe

Score 85/100

Cielo WooCommerce – Solução Webservice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'cielo-woocommerce' plugin v4.0.14 exhibits a generally good security posture based on the provided static analysis. The absence of direct attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, coupled with a complete lack of dangerous functions and raw SQL queries, suggests a well-hardened codebase. The high percentage of properly escaped output (90%) and the presence of capability checks further bolster this positive assessment. However, the analysis does highlight a single flow with an unsanitized path, which, while not classified as critical or high severity in the taint analysis, warrants attention as it represents a potential avenue for injection or manipulation if exploited. Furthermore, the plugin makes an external HTTP request, and the lack of nonce checks is a notable concern, especially if any internal functionality relies on user-initiated actions that are not adequately protected. The plugin's clean vulnerability history with zero recorded CVEs is a significant strength, indicating a history of responsible development and patching, or a lack of historically exploitable weaknesses.

Key Concerns

  • Flow with unsanitized path detected
  • External HTTP request made
  • No nonce checks present
Vulnerabilities
None known

Cielo WooCommerce – Solução Webservice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cielo WooCommerce – Solução Webservice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
76 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

90% escaped84 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-wc-cielo-helper> (includes\class-wc-cielo-helper.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Cielo WooCommerce – Solução Webservice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitcielo-woocommerce.php:59
filterwoocommerce_payment_gatewayscielo-woocommerce.php:67
actionwp_enqueue_scriptscielo-woocommerce.php:68
actionadmin_noticescielo-woocommerce.php:75
actionplugins_loadedcielo-woocommerce.php:246
actionhttp_api_curlincludes\class-wc-cielo-api.php:287
actionwoocommerce_api_wc_cielo_credit_gatewayincludes\class-wc-cielo-credit-gateway.php:59
actionwp_enqueue_scriptsincludes\class-wc-cielo-credit-gateway.php:62
filterwoocommerce_get_order_item_totalsincludes\class-wc-cielo-credit-gateway.php:65
actionwoocommerce_api_wc_cielo_debit_gatewayincludes\class-wc-cielo-debit-gateway.php:55
actionwp_enqueue_scriptsincludes\class-wc-cielo-debit-gateway.php:58
filterwoocommerce_get_order_item_totalsincludes\class-wc-cielo-debit-gateway.php:61
Maintenance & Trust

Cielo WooCommerce – Solução Webservice Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 10, 2020
PHP min version
Downloads41K

Community Trust

Rating96/100
Number of ratings72
Active installs300
Developer Profile

Cielo WooCommerce – Solução Webservice Developer Profile

Gabriel Reguly

2 plugins · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cielo WooCommerce – Solução Webservice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cielo-woocommerce/assets/css/checkout-icons.css/wp-content/plugins/cielo-woocommerce/assets/css/checkout-webservice.css
Version Parameters
cielo-woocommerce/assets/css/checkout-icons.css?ver=cielo-woocommerce/assets/css/checkout-webservice.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Cielo WooCommerce – Solução Webservice