Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Security & Risk Analysis

wordpress.org/plugins/click2pay-pagamentos

Ofereça a seus clientes pagamentos via Pix, assinatura recorrente, cartão de crédito ou boleto bancário, com as melhores tarifas!

40 active installs v1.3.0 PHP 7.4+ WP + Updated Jul 17, 2024
assinaturasboletocartao-de-creditogatewaypix
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Safe to Use in 2026?

Generally Safe

Score 92/100

Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the click2pay-pagamentos plugin v1.3.0 reveals a generally strong security posture. The plugin demonstrates good development practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks, resulting in a minimal attack surface. The code also shows a commitment to secure coding by utilizing prepared statements for all SQL queries and implementing nonce and capability checks. Furthermore, the absence of known CVEs and a clean vulnerability history indicate responsible maintenance and a lack of publicly disclosed security flaws.

However, a few areas warrant attention. While the vast majority of output is properly escaped, a small percentage remains unescaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if an attacker can control the unescaped output. The presence of file operations and external HTTP requests, while not inherently malicious, introduces potential vectors for exploitation if not handled with extreme care and sanitization. The taint analysis showing zero flows is a positive sign, but it's important to remember that taint analysis is not foolproof and might miss certain complex vulnerabilities.

Overall, the click2pay-pagamentos plugin appears to be developed with security in mind, exhibiting several best practices. The limited unescaped output and the presence of file/HTTP operations are minor concerns that could be addressed to further strengthen its security. The clean vulnerability history is a significant positive indicator.

Key Concerns

  • Unescaped output detected
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
81 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped98 total outputs
Attack Surface

Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionadmin_noticesclick2pay-pagamentos.php:62
actionbefore_woocommerce_initclick2pay-pagamentos.php:96
filterwoocommerce_payment_gatewaysclick2pay-pagamentos.php:102
filterwoocommerce_payment_methods_typesclick2pay-pagamentos.php:104
filterwoocommerce_payment_token_classclick2pay-pagamentos.php:105
actionplugins_loadedclick2pay-pagamentos.php:223
actionwc_ajax_click2pay_order_is_paidsrc\Ajax\Pix.php:11
actionwoocommerce_before_thankyousrc\Gateways\Bank_Slip.php:90
actionwoocommerce_email_before_order_tablesrc\Gateways\Bank_Slip.php:92
actionwp_enqueue_scriptssrc\Gateways\Bank_Slip.php:96
filterwoocommerce_my_account_my_orders_actionssrc\Gateways\Bank_Slip.php:98
filterwoocommerce_credit_card_form_fieldssrc\Gateways\Credit_Card.php:96
actionwoocommerce_before_thankyousrc\Gateways\Credit_Card.php:98
actionwp_enqueue_scriptssrc\Gateways\Credit_Card.php:102
filterwoocommerce_get_order_item_totalssrc\Gateways\Credit_Card.php:105
filteroption_wcbcf_settingssrc\Gateways\Credit_Card.php:107
filterwoocommerce_subscription_payment_metasrc\Gateways\Credit_Card_Subscriptions.php:41
filterwoocommerce_subscription_status_activesrc\Gateways\Credit_Card_Subscriptions.php:43
filterwcs_renewal_order_createdsrc\Gateways\Credit_Card_Subscriptions.php:45
actionwoocommerce_before_thankyousrc\Gateways\Pix.php:84
actionwoocommerce_email_before_order_tablesrc\Gateways\Pix.php:87
actionwp_enqueue_scriptssrc\Gateways\Pix.php:92
filterwoocommerce_my_account_my_orders_actionssrc\Gateways\Pix.php:94
filterwoocommerce_valid_order_statuses_for_paymentsrc\Gateways\Pix.php:96
filterthwcfe_disabled_fieldssrc\Integrations\Woocommerce_Checkout_Field_Editor.php:10
actionywsbs_customer_subscription_payment_done_mailsrc\Yith_Subscriptions\Hooks.php:13
actionywsbs_subscription_status_activesrc\Yith_Subscriptions\Hooks.php:14
actionywsbs_renew_subscriptionsrc\Yith_Subscriptions\Hooks.php:16
actionywsbs_subscription_loadedsrc\Yith_Subscriptions\Hooks.php:18
Maintenance & Trust

Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 17, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário Developer Profile

Click2Pay

1 plugin · 40 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário