Contabilium Oficial para WooCommerce Security & Risk Analysis

wordpress.org/plugins/contabilium-oficial-para-woo

Contabilium es un sistema de gestión online que te permite administrar todos tus ingresos y gastos de una forma sencilla y rápida en cualquier momento …

300 active installs v3.0.0 PHP + WP 3.5.0+ Updated Jun 9, 2025
contabiliumerpfacturacion-electronicasync-stockwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contabilium Oficial para WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Contabilium Oficial para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The plugin 'contabilium-oficial-para-woo' v3.0.0 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded for this plugin, and the taint analysis shows no critical or high severity flows with unsanitized paths. The majority of SQL queries utilize prepared statements, which is a strong security practice. However, significant concerns arise from the static analysis. The plugin exposes two REST API routes without any permission callbacks, creating a substantial attack surface that is completely unprotected. Additionally, a considerable percentage of output escaping is not properly handled (36%), which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. The complete absence of nonce checks on entry points further exacerbates these risks, particularly for the unprotected REST API routes, as it opens the door for CSRF attacks. While the lack of known vulnerabilities is encouraging, the identified vulnerabilities in the code's access control and output sanitization represent clear and present risks.

Key Concerns

  • REST API routes without permission callbacks
  • Output escaping not properly handled
  • No nonce checks on entry points
Vulnerabilities
None known

Contabilium Oficial para WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contabilium Oficial para WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
18 prepared
Unescaped Output
48
86 escaped
Nonce Checks
0
Capability Checks
4
File Operations
4
External Requests
10
Bundled Libraries
0

SQL Query Safety

82% prepared22 total queries

Output Escaping

64% escaped134 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
contabilium_config_page_html (3.0.1\contabilium-oficial-woo.php:205)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Contabilium Oficial para WooCommerce Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

POST/wp-json/wp/v2/webhook/(?P<integration_id>\S+)3.0.1\api.php:10
POST/wp-json/wp/v2/webhook/(?P<integration_id>\S+)api.php:10
WordPress Hooks 22
actionrest_api_init3.0.1\api.php:9
actionadmin_menu3.0.1\contabilium-oficial-woo.php:110
filterwoocommerce_webhook_payload3.0.1\contabilium-oficial-woo.php:112
filterwoocommerce_max_webhook_delivery_failures3.0.1\contabilium-oficial-woo.php:114
actionadmin_notices3.0.1\contabilium-oficial-woo.php:745
actionadmin_head3.0.1\contabilium-oficial-woo.php:792
actionadd_meta_boxes3.0.1\contabilium-oficial-woo.php:839
actionadmin_head3.0.1\contabilium-oficial-woo.php:898
filterwoocommerce_checkout_fields3.0.1\includes\manage-orders.php:342
actionwoocommerce_checkout_process3.0.1\includes\manage-orders.php:360
actionwoocommerce_checkout_update_order_meta3.0.1\includes\manage-orders.php:428
actionrest_api_initapi.php:9
actionadmin_menucontabilium-oficial-woo.php:110
filterwoocommerce_webhook_payloadcontabilium-oficial-woo.php:112
filterwoocommerce_max_webhook_delivery_failurescontabilium-oficial-woo.php:114
actionadmin_noticescontabilium-oficial-woo.php:745
actionadmin_headcontabilium-oficial-woo.php:792
actionadd_meta_boxescontabilium-oficial-woo.php:839
actionadmin_headcontabilium-oficial-woo.php:898
filterwoocommerce_checkout_fieldsincludes\manage-orders.php:342
actionwoocommerce_checkout_processincludes\manage-orders.php:360
actionwoocommerce_checkout_update_order_metaincludes\manage-orders.php:428
Maintenance & Trust

Contabilium Oficial para WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 9, 2025
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Contabilium Oficial para WooCommerce Developer Profile

contabilium

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contabilium Oficial para WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contabilium-oficial-para-woo/images/logo-icon.svg
Version Parameters
contabilium-oficial-para-woo/style.css?ver=contabilium-oficial-para-woo/contabilium.js?ver=

HTML / DOM Fingerprints

CSS Classes
contabilium-banner-image
HTML Comments
<tr> <td style="background-color: #f2f2f2;" align="center"> <img src="https://app.contabilium.com/images/mails/Contabilium_logo_horizontal.png" width="50%" height="50%"> </td> </tr>
Data Attributes
id="contabilium-config-form"id="contabilium_api_client_id"id="contabilium_api_client_secret"id="contabilium_api_country"id="contabilium_api_integration"id="contabilium_sync_price_with_iva"+9 more
JS Globals
window.contabilium_product_sync_processwindow.contabilium_product_sync_process_stopwindow.contabilium_order_sync_processwindow.contabilium_order_sync_process_stop
FAQ

Frequently Asked Questions about Contabilium Oficial para WooCommerce