Comprobante de Pago Perú Security & Risk Analysis

wordpress.org/plugins/comprobante-de-pago-peru

Payment Receipt for Peru where the option to choose bill or Invoice or others is added.

200 active installs v0.2.0 PHP 7.4+ WP 5.2+ Updated Jan 16, 2025
boletadnifacturaperuruc
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comprobante de Pago Perú Safe to Use in 2026?

Generally Safe

Score 92/100

Comprobante de Pago Perú has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'comprobante-de-pago-peru' v0.2.0 presents a generally positive security posture based on the provided static analysis. The absence of any identified CVEs in its history and the lack of critical or high-severity taint flows are strong indicators of careful development. Furthermore, the code does not appear to have immediate vulnerabilities related to SQL injection, as all queries utilize prepared statements. The attack surface is also commendably small, with no registered AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers.

However, there are areas for improvement. A notable concern is the low percentage of properly escaped output (38%). This could expose the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed to users. Additionally, the complete absence of nonce checks and capability checks, while not directly flagged as vulnerabilities in this analysis, indicates a potential lack of robust authorization and security mechanisms, especially if any future functionality introduces unprotected entry points. The limited scope of the static analysis (0 flows analyzed) also means that deeper, more complex vulnerabilities might not have been detected.

In conclusion, the plugin exhibits a strong foundation with no known critical vulnerabilities and a small attack surface. The primary weakness lies in output sanitization, which requires immediate attention. While the vulnerability history is clean, the lack of comprehensive security checks like nonces and capability checks, combined with potential undiscovered issues due to limited taint analysis, suggests that ongoing vigilance and code review are essential for maintaining security.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Comprobante de Pago Perú Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Comprobante de Pago Perú Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped24 total outputs
Attack Surface

Comprobante de Pago Perú Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionbefore_woocommerce_initcomprobante-de-pago-peru.php:30
actioninitcomprobante-de-pago-peru.php:41
actionadmin_menucomprobante_admin.php:8
actionadmin_initcomprobante_admin.php:13
actionadmin_noticescomprobante_admin.php:148
actionadmin_noticescomprobante_admin.php:155
actionwoocommerce_before_checkout_billing_formcomprobante_checkout.php:57
actionwp_enqueue_scriptscomprobante_checkout.php:73
filterwoocommerce_checkout_fieldscomprobante_checkout.php:83
actionwoocommerce_checkout_processcomprobante_checkout.php:139
filterwoocommerce_form_fieldcomprobante_checkout.php:161
actionwoocommerce_checkout_update_order_metacomprobante_checkout.php:170
actionwoocommerce_admin_order_data_after_billing_addresscomprobante_checkout.php:180
actionwoocommerce_email_after_order_tablecomprobante_checkout.php:189
actionwoocommerce_thankyoucomprobante_checkout.php:199
filterwoocommerce_rest_prepare_shop_order_objectcomprobante_checkout.php:213
Maintenance & Trust

Comprobante de Pago Perú Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 16, 2025
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Comprobante de Pago Perú Developer Profile

Renzo Tejada

11 plugins · 9K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
327 days
View full developer profile
Detection Fingerprints

How We Detect Comprobante de Pago Perú

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comprobante-de-pago-peru/js/comprobante.js
Script Paths
js/comprobante.js
Version Parameters
comprobante-de-pago-peru/js/comprobante.js?ver=

HTML / DOM Fingerprints

CSS Classes
form-row-wide
Data Attributes
billing_comprobantebilling_dnibilling_rucbilling_responsable
FAQ

Frequently Asked Questions about Comprobante de Pago Perú