EBANX Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/ebanx-payment-gateway-for-woocommerce

Offer Latin American local payment methods & increase your conversion rates with the solution used by AliExpress, AirBnB and Spotify in Brazil.

30 active installs v1.41.3 PHP + WP 4.0+ Updated Jun 19, 2020
boletocredit-cardebanxpayment-gatewaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EBANX Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

EBANX Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The EBANX Payment Gateway for WooCommerce plugin version 1.41.3 presents a mixed security posture. On the positive side, it demonstrates good practices by heavily utilizing prepared statements for SQL queries and ensuring a high percentage of outputs are properly escaped. The absence of known CVEs and common vulnerability types in its history is also a strong indicator of past security diligence. However, the static analysis reveals a significant concern regarding its attack surface. With two AJAX handlers identified, both lacking proper authentication checks, there is a direct and accessible entry point for potential malicious actors. The limited taint analysis showing no critical or high-severity flows is reassuring, but the lack of analysis on flows with unsanitized paths means this area is not fully explored. The presence of a nonce check and capability checks on some entry points is positive, but does not mitigate the risk posed by the unprotected AJAX handlers.

Key Concerns

  • AJAX handlers without auth checks
  • Limited taint flow analysis (no unsanitized paths)
Vulnerabilities
None known

EBANX Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EBANX Payment Gateway for WooCommerce Release Timeline

v1.41.3Current
v1.41.2
v1.41.1
v1.41.0
v1.40.6
v1.40.5
v1.40.4
v1.40.3
v1.40.2
v1.40.1
v1.40.0
v1.39.1
v1.39.0
v1.38.5
v1.38.4
v1.38.3
v1.38.2
v1.38.1
v1.38.0
v1.37.3
Code Analysis
Analyzed Mar 16, 2026

EBANX Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
26
512 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

95% escaped538 total outputs
Attack Surface
2 unprotected

EBANX Payment Gateway for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_ebanx_update_converted_valuegateways\class-wc-ebanx-gateway.php:11
authwp_ajax_ebanx_update_converted_valuegateways\class-wc-ebanx-gateway.php:12
WordPress Hooks 42
actionwoocommerce_order_edit_statusgateways\class-wc-ebanx-credit-card-gateway.php:38
actionwcs_default_retry_rulesgateways\class-wc-ebanx-credit-card-gateway.php:51
actionwoocommerce_scheduled_subscription_paymentgateways\class-wc-ebanx-credit-card-gateway.php:52
actionwp_enqueue_scriptsgateways\class-wc-ebanx-gateway.php:88
filterwoocommerce_checkout_fieldsgateways\class-wc-ebanx-gateway.php:90
actionwp_enqueue_scriptsgateways\class-wc-ebanx-new-gateway.php:127
filterwoocommerce_checkout_fieldsgateways\class-wc-ebanx-new-gateway.php:128
actionwp_enqueue_scriptsservices\class-wc-ebanx-one-click.php:79
actionwoocommerce_after_add_to_cart_formservices\class-wc-ebanx-one-click.php:80
actionwp_loadedservices\class-wc-ebanx-one-click.php:81
actionwp_enqueue_scriptsservices\class-wc-ebanx-third-party-compability-layer.php:15
actionplugins_loadedwoocommerce-gateway-ebanx.php:125
actionwp_loadedwoocommerce-gateway-ebanx.php:126
actioninitwoocommerce-gateway-ebanx.php:128
actioninitwoocommerce-gateway-ebanx.php:129
actionadmin_initwoocommerce-gateway-ebanx.php:130
actionadmin_initwoocommerce-gateway-ebanx.php:131
actionadmin_initwoocommerce-gateway-ebanx.php:134
actionadmin_initwoocommerce-gateway-ebanx.php:135
actionadmin_headwoocommerce-gateway-ebanx.php:138
actionwoocommerce_order_actionswoocommerce-gateway-ebanx.php:140
actionwoocommerce_order_action_ebanx_capture_orderwoocommerce-gateway-ebanx.php:141
actionadmin_footerwoocommerce-gateway-ebanx.php:143
actionwoocommerce_settings_save_checkoutwoocommerce-gateway-ebanx.php:145
actionwoocommerce_settings_savedwoocommerce-gateway-ebanx.php:146
actionwoocommerce_settings_savedwoocommerce-gateway-ebanx.php:147
actionwoocommerce_settings_savedwoocommerce-gateway-ebanx.php:148
actionwoocommerce_settings_savedwoocommerce-gateway-ebanx.php:149
actionwoocommerce_admin_order_data_after_order_detailswoocommerce-gateway-ebanx.php:151
actionupgrader_process_completewoocommerce-gateway-ebanx.php:153
actionwoocommerce_checkout_processwoocommerce-gateway-ebanx.php:155
actionwoocommerce_order_actions_endwoocommerce-gateway-ebanx.php:160
actionsave_postwoocommerce-gateway-ebanx.php:161
actioninitwoocommerce-gateway-ebanx.php:169
filterquery_varswoocommerce-gateway-ebanx.php:172
filterwoocommerce_account_menu_itemswoocommerce-gateway-ebanx.php:173
filterthe_titlewoocommerce-gateway-ebanx.php:174
filterwoocommerce_payment_gatewayswoocommerce-gateway-ebanx.php:180
filterwoocommerce_my_account_my_orders_actionswoocommerce-gateway-ebanx.php:182
filterwoocommerce_admin_order_actionswoocommerce-gateway-ebanx.php:183
actionwoocommerce_admin_order_data_after_billing_addresswoocommerce-gateway-ebanx.php:185
actionplugins_loadedwoocommerce-gateway-ebanx.php:896
Maintenance & Trust

EBANX Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 19, 2020
PHP min version
Downloads19K

Community Trust

Rating74/100
Number of ratings10
Active installs30
Developer Profile

EBANX Payment Gateway for WooCommerce Developer Profile

EBANX

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EBANX Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/js/admin-dashboard.js/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/css/admin-dashboard.css/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/js/checkout.js/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/css/checkout.css/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/js/my-account.js/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/css/my-account.css/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/js/onepay.js/wp-content/plugins/ebanx-payment-gateway-for-woocommerce/assets/js/admin-order-details.js+4 more
Version Parameters
ebanx-payment-gateway-for-woocommerce/assets/js/admin-dashboard.js?ver=ebanx-payment-gateway-for-woocommerce/assets/css/admin-dashboard.css?ver=ebanx-payment-gateway-for-woocommerce/assets/js/checkout.js?ver=ebanx-payment-gateway-for-woocommerce/assets/css/checkout.css?ver=ebanx-payment-gateway-for-woocommerce/assets/js/my-account.js?ver=ebanx-payment-gateway-for-woocommerce/assets/css/my-account.css?ver=ebanx-payment-gateway-for-woocommerce/assets/js/onepay.js?ver=ebanx-payment-gateway-for-woocommerce/assets/js/admin-order-details.js?ver=ebanx-payment-gateway-for-woocommerce/assets/js/wc-ebanx-helpers.js?ver=ebanx-payment-gateway-for-woocommerce/assets/css/wc-ebanx-helpers.css?ver=ebanx-payment-gateway-for-woocommerce/assets/js/modal.js?ver=ebanx-payment-gateway-for-woocommerce/assets/css/modal.css?ver=

HTML / DOM Fingerprints

CSS Classes
ebanx-saved-cardsebanx-checkout-wrapperebanx-checkout-buttonebanx-checkout-formebanx-checkout-fieldebanx-checkout-labelebanx-checkout-inputebanx-checkout-error+10 more
HTML Comments
<!-- EBANX Payment Gateway for WooCommerce --><!-- EBANX Settings --><!-- EBANX Checkout Form --><!-- EBANX Modal Container -->
Data Attributes
data-ebanx-gateway-settingsdata-ebanx-checkout-urldata-ebanx-order-iddata-ebanx-modal-target
JS Globals
window.WC_EBANX_Adminwindow.WC_EBANX_Checkoutwindow.WC_EBANX_MyAccountwindow.WC_EBANX_Modalwindow.WC_EBANX_Helpers
REST Endpoints
/wp-json/ebanx/v1/capture-payment/wp-json/ebanx/v1/cancel-order/wp-json/ebanx/v1/create-payment-link
FAQ

Frequently Asked Questions about EBANX Payment Gateway for WooCommerce