
Eupago Gateway For Woocommerce Security & Risk Analysis
wordpress.org/plugins/eupago-gateway-for-woocommercePlugin para recebimento de pagamentos via Multibanco, PayShop, MB WAY, Cartão de Crédito, Paysafecard, CofidisPay, Bizum e EuroPix.
Is Eupago Gateway For Woocommerce Safe to Use in 2026?
Mostly Safe
Score 76/100Eupago Gateway For Woocommerce is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "eupago-gateway-for-woocommerce" plugin v4.7.1 presents a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high rate of output escaping, several significant concerns exist. The presence of two AJAX handlers without authentication checks directly exposes potential attack vectors. The taint analysis indicates two flows with unsanitized paths, although they are not classified as critical or high severity, they still represent a risk of unintended data manipulation or exposure.
The vulnerability history is particularly concerning. With two known CVEs, one of which remains unpatched, and both being medium severity, this indicates a pattern of recurring security weaknesses. The common vulnerability types of Missing Authorization and Cross-Site Request Forgery (CSRF) align with the static analysis findings of unprotected AJAX handlers. While the plugin has strengths in its database query handling and output sanitization, the unpatched vulnerability and the exposed AJAX endpoints are critical issues that significantly detract from its overall security.
In conclusion, the plugin has some sound security foundations, but the existing unpatched vulnerability and the directly exploitable AJAX endpoints necessitate immediate attention. The recurring nature of these vulnerability types suggests a need for more robust security review and testing within the development lifecycle.
Key Concerns
- Unpatched CVE
- AJAX handlers without auth checks
- Flows with unsanitized paths
Eupago Gateway For Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Eupago Gateway For Woocommerce <= 4.6.3 - Missing Authorization
Eupago Gateway For Woocommerce <= 3.1.9 - Cross-Site Request Forgery via eupago_page_content
Eupago Gateway For Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Eupago Gateway For Woocommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 92
Maintenance & Trust
Eupago Gateway For Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Eupago Gateway For Woocommerce Alternatives
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
Eupago Gateway For Woocommerce Developer Profile
1 plugin · 2K total installs
How We Detect Eupago Gateway For Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eupago-gateway-for-woocommerce/assets/css/eupago-gateway-for-woocommerce.css/wp-content/plugins/eupago-gateway-for-woocommerce/assets/js/eupago-gateway-for-woocommerce.js/wp-content/plugins/eupago-gateway-for-woocommerce/assets/js/eupago-admin-scripts.js/wp-content/plugins/eupago-gateway-for-woocommerce/assets/js/eupago-checkout.js/wp-content/plugins/eupago-gateway-for-woocommerce/assets/css/eupago-gateway-for-woocommerce.css?ver=/wp-content/plugins/eupago-gateway-for-woocommerce/assets/js/eupago-gateway-for-woocommerce.js?ver=/wp-content/plugins/eupago-gateway-for-woocommerce/assets/js/eupago-admin-scripts.js?ver=/wp-content/plugins/eupago-gateway-for-woocommerce/assets/js/eupago-checkout.js?ver=HTML / DOM Fingerprints
eupago-terms-messageeupago-admin-noticeeupago-payment-method-mbwayeupago-payment-method-payshopeupago-payment-method-credit-cardeupago-payment-method-cofidispayeupago-payment-method-bizumeupago-payment-method-europix<!-- eupago_order_meta_box --><!-- eupago_vat_number_field -->data-eupago-methoddata-eupago-multibanco-entitydata-eupago-multibanco-subentitydata-eupago-mbway-phonedata-eupago-payshop-terminaleupago_params