
Contabilium Oficial para WooCommerce Security & Risk Analysis
wordpress.org/plugins/contabilium-oficial-para-wooContabilium es un sistema de gestión online que te permite administrar todos tus ingresos y gastos de una forma sencilla y rápida en cualquier momento …
Is Contabilium Oficial para WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Contabilium Oficial para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'contabilium-oficial-para-woo' v3.0.0 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded for this plugin, and the taint analysis shows no critical or high severity flows with unsanitized paths. The majority of SQL queries utilize prepared statements, which is a strong security practice. However, significant concerns arise from the static analysis. The plugin exposes two REST API routes without any permission callbacks, creating a substantial attack surface that is completely unprotected. Additionally, a considerable percentage of output escaping is not properly handled (36%), which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. The complete absence of nonce checks on entry points further exacerbates these risks, particularly for the unprotected REST API routes, as it opens the door for CSRF attacks. While the lack of known vulnerabilities is encouraging, the identified vulnerabilities in the code's access control and output sanitization represent clear and present risks.
Key Concerns
- REST API routes without permission callbacks
- Output escaping not properly handled
- No nonce checks on entry points
Contabilium Oficial para WooCommerce Security Vulnerabilities
Contabilium Oficial para WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Contabilium Oficial para WooCommerce Attack Surface
REST API Routes 2
WordPress Hooks 22
Maintenance & Trust
Contabilium Oficial para WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Contabilium Oficial para WooCommerce Alternatives
Afterpay Gateway for WooCommerce
afterpay-gateway-for-woocommerce
Provide Afterpay as a payment option for WooCommerce orders.
Holded integration
holded-integration
Holded service integration with WooCommerce
Riverty Payments for Woocommerce
afterpay-payment-gateway-for-woocommerce
Riverty is the most consumer-friendly BNPL payment method in Germany, Austria, Switzerland, the Nordics, Netherlands and Belgium.
Linet ERP Integration For Woocommerce
linet-erp-woocommerce-integration
After installing this plugin you can sync woocommerce with Linet ERP.
Splash Sync
splash-connector
Splash Sync, the synchronization system of innovative companies! Synchronize your website with all your business applications.
Contabilium Oficial para WooCommerce Developer Profile
1 plugin · 300 total installs
How We Detect Contabilium Oficial para WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contabilium-oficial-para-woo/images/logo-icon.svgcontabilium-oficial-para-woo/style.css?ver=contabilium-oficial-para-woo/contabilium.js?ver=HTML / DOM Fingerprints
contabilium-banner-image<tr>
<td style="background-color: #f2f2f2;" align="center">
<img src="https://app.contabilium.com/images/mails/Contabilium_logo_horizontal.png" width="50%" height="50%">
</td>
</tr>id="contabilium-config-form"id="contabilium_api_client_id"id="contabilium_api_client_secret"id="contabilium_api_country"id="contabilium_api_integration"id="contabilium_sync_price_with_iva"+9 morewindow.contabilium_product_sync_processwindow.contabilium_product_sync_process_stopwindow.contabilium_order_sync_processwindow.contabilium_order_sync_process_stop