Plugin de Clip para WooCommerce Security & Risk Analysis

wordpress.org/plugins/clip-for-woocommerce

Ofrece a tus clientes pagos con todas las tarjetas, incluso efectivo y obtén tus depósitos en 24 horas con el plugin oficial de Clip.

800 active installs v2.1.7 PHP 7.0+ WP 5.0+ Updated Mar 12, 2026
woocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Plugin de Clip para WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Plugin de Clip para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "clip-for-woocommerce" plugin v2.1.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output, minimizing risks of SQL injection and reflected/stored XSS. The absence of dangerous functions, external HTTP requests, and critical or high severity taint flows further contributes to its stability. However, a significant concern arises from its attack surface, with 3 AJAX handlers identified, all of which lack authentication checks. This exposes these entry points to potential unauthorized access and manipulation by unauthenticated users.

The vulnerability history is currently clean, with no known CVEs recorded. This suggests a potentially well-maintained codebase or a lack of past exploitation. Despite the absence of past vulnerabilities, the identified unprotected AJAX endpoints represent a tangible and immediate risk. The presence of file operations, while not explicitly flagged as risky without further context, could become a vector if not handled with extreme care and proper sanitization, especially in combination with the unprotected AJAX handlers.

In conclusion, while the plugin adheres to several secure coding principles, the unprotected AJAX handlers present a critical weakness that needs immediate attention. The lack of historical vulnerabilities is encouraging but does not negate the inherent risks posed by the current code. Addressing these unprotected entry points should be the priority to strengthen the plugin's overall security.

Key Concerns

  • AJAX handlers without auth checks
  • Unprotected entry points
  • File operations without clear sanitization context
Vulnerabilities
None known

Plugin de Clip para WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plugin de Clip para WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
133 escaped
Nonce Checks
4
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped145 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
render (src\gateway\class-post-checkout.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Plugin de Clip para WooCommerce Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_clip_save_settingshooks.php:41
authwp_ajax_clip_request_deposit_actionhooks.php:52
noprivwp_ajax_clip_request_deposit_actionhooks.php:69
WordPress Hooks 15
actionplugins_loadedclip-for-woocommerce.php:22
actionactivated_pluginclip-for-woocommerce.php:23
actiondeactivated_pluginclip-for-woocommerce.php:24
actionbefore_woocommerce_initclip-for-woocommerce.php:304
actionbefore_woocommerce_initclip-for-woocommerce.php:324
actionwoocommerce_blocks_loadedclip-for-woocommerce.php:327
actionwoocommerce_blocks_payment_method_type_registrationclip-for-woocommerce.php:339
filterwoocommerce_payment_gatewayshooks.php:20
filterwoocommerce_available_payment_gatewayshooks.php:21
actionadmin_menuhooks.php:30
actionwp_enqueue_scriptshooks.php:49
actionwoocommerce_api_wc-cliphooks.php:61
actionadmin_enqueue_scriptshooks.php:78
actionadmin_enqueue_scriptshooks.php:79
actionadmin_enqueue_scriptssrc\gateway\class-wc-clip-redirect.php:229
Maintenance & Trust

Plugin de Clip para WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 12, 2026
PHP min version7.0
Downloads17K

Community Trust

Rating36/100
Number of ratings5
Active installs800
Developer Profile

Plugin de Clip para WooCommerce Developer Profile

payclip

2 plugins · 840 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin de Clip para WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clip-for-woocommerce/assets/css/settings.css/wp-content/plugins/clip-for-woocommerce/assets/js/admin-settings.js/wp-content/plugins/clip-for-woocommerce/assets/js/gateway.js
Version Parameters
clip-for-woocommerce/assets/css/settings.css?ver=clip-for-woocommerce/assets/js/admin-settings.js?ver=clip-for-woocommerce/assets/js/gateway.js?ver=

HTML / DOM Fingerprints

CSS Classes
wc_clipredirect_payment_options
Data Attributes
data-clipredirect-url
JS Globals
wc_clipredirect_params
FAQ

Frequently Asked Questions about Plugin de Clip para WooCommerce