
Culqi Security & Risk Analysis
wordpress.org/plugins/culqi-checkoutConéctate a nuestra pasarela de pago CulqiOnline de forma segura y estable en tu tienda virtual.
Is Culqi Safe to Use in 2026?
Generally Safe
Score 92/100Culqi has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "culqi-checkout" v3.1.4 plugin exhibits a generally good security posture, with strong practices in SQL query handling and output escaping, indicating developers are mindful of common web vulnerabilities. The plugin effectively utilizes prepared statements for all SQL queries and demonstrates a high percentage of properly escaped outputs, minimizing risks of SQL injection and cross-site scripting (XSS) through these vectors. The absence of critical or high severity taint flows further reinforces this positive assessment, suggesting that user-supplied data is being handled with care within the analyzed code paths. Additionally, the plugin leverages nonces and capability checks for most of its AJAX handlers.
However, a notable concern arises from the presence of 4 AJAX handlers without any authentication or authorization checks. This directly exposes these entry points to potential abuse by unauthenticated users, creating a significant attack surface. While no specific vulnerabilities were identified in the static analysis related to these unprotected handlers, their existence represents a clear risk. The plugin's vulnerability history, which includes one medium severity Server-Side Request Forgery (SSRF) vulnerability in the past, even though currently patched, indicates a past oversight in handling external requests or data that could be manipulated. This history, combined with the unprotected AJAX handlers, suggests a need for continued vigilance and robust security reviews.
In conclusion, the "culqi-checkout" plugin demonstrates strong foundational security practices, particularly in data handling and sanitization. The developers have shown commitment to secure coding by addressing past vulnerabilities. The primary weakness lies in the exposed AJAX endpoints, which should be prioritized for immediate security hardening. A balanced view acknowledges the strengths in code quality while highlighting the critical need to secure the identified unprotected entry points to further mitigate potential risks.
Key Concerns
- 4 AJAX handlers without auth checks
- 1 medium severity CVE in vulnerability history
Culqi Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Culqi <= 3.0.14 - Authenticated (Subscriber+) Server-Side Request Forgery
Culqi Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Culqi Attack Surface
AJAX Handlers 14
WordPress Hooks 53
Maintenance & Trust
Culqi Maintenance & Trust
Maintenance Signals
Community Trust
Culqi Alternatives
Culqi Full Integracion
culqi-full-integration
Podrás hacer pagos desde Woocommerce usando el servicio de Culqi, además de reembolsos, estados, logs y personalizaciones del modal de pago.
Payment Gateway Per Product for WooCommerce
woocommerce-product-payments
Control WooCommerce payment gateways per product, category, or tag. Show the right payment methods at checkout and increase conversions.
Default Payment Gateway for WooCommerce
hw-default-payment-gateway-for-woocommerce
Manage the default chosen Payment method on checkout, easily!
Habibur Multi-Gateway Manager for WooCommerce
habibur-multi-gateway-manager-for-woocommerce
Dynamically manage, sort, and apply conditional logic to WooCommerce payment gateways — no code needed.
HustlePay Payment Connector for WooCommerce
hustlepay-payment-connector-for-woocommerce
Connect WooCommerce to HustlePay checkout orchestration while payment processing stays with your configured payment service providers.
Culqi Developer Profile
1 plugin · 1K total installs
How We Detect Culqi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/culqi-checkout/admin/assets/css/fullculqi_admin.css/wp-content/plugins/culqi-checkout/admin/assets/css/fullculqi_addons.css/wp-content/plugins/culqi-checkout/admin/assets/js/fullculqi_admin.jsculqi-checkout/admin/assets/css/fullculqi_admin.css?_=culqi-checkout/admin/assets/css/fullculqi_addons.css?_=culqi-checkout/admin/assets/js/fullculqi_admin.js?_=HTML / DOM Fingerprints
fullculqi