Global Pays – Payments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/global-pays-payments-for-woocommerce

PIX, Boleto and credit card payments in WooCommerce.

0 active installs v1.0.5 PHP 7.4+ WP 6.1+ Updated Oct 29, 2025
boletocreditopagamentospixwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Global Pays – Payments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Global Pays – Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "global-pays-payments-for-woocommerce" plugin, version 1.0.5, exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and achieving a high rate of output escaping (89%). The absence of any recorded vulnerabilities or CVEs in its history is also a strong indicator of diligent security development. However, significant concerns arise from the attack surface analysis. All six identified AJAX handlers lack authentication checks, presenting a direct pathway for unauthorized access and potential manipulation of plugin functionalities. The lack of taint analysis data means we cannot definitively rule out unsanitized input vulnerabilities, though the absence of critical or high severity flows in the limited analysis is a positive sign.

Despite the strong foundation in SQL handling and output sanitization, the unprotected AJAX endpoints represent a critical weakness. This means an attacker could potentially trigger these functions without any verification of user privileges. While no historical vulnerabilities are recorded, this does not guarantee future safety, especially given the exposed attack surface. The plugin would benefit greatly from implementing capability checks on all its AJAX handlers to mitigate the identified risks.

Key Concerns

  • Unprotected AJAX handlers
  • Limited taint analysis coverage
  • No capability checks on AJAX
Vulnerabilities
None known

Global Pays – Payments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Global Pays – Payments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
159 escaped
Nonce Checks
3
Capability Checks
0
File Operations
1
External Requests
5
Bundled Libraries
0

Output Escaping

89% escaped178 total outputs
Attack Surface
6 unprotected

Global Pays – Payments for WooCommerce Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_acgpfw_installmentsincludes\class\start.php:83
noprivwp_ajax_acgpfw_installmentsincludes\class\start.php:84
authwp_ajax_acgpfw_set_installmentsincludes\class\start.php:85
noprivwp_ajax_acgpfw_set_installmentsincludes\class\start.php:86
authwp_ajax_acgpfw_check_order_statusincludes\class\start.php:87
noprivwp_ajax_acgpfw_check_order_statusincludes\class\start.php:88
WordPress Hooks 30
actionplugins_loadedglobal-pays-payments-for-woocommerce.php:22
actionadmin_noticesglobal-pays-payments-for-woocommerce.php:24
actionwoocommerce_rest_checkout_process_payment_with_contextincludes\class\blocks_support_boleto.php:21
actionwoocommerce_rest_checkout_process_payment_with_contextincludes\class\blocks_support_credit.php:21
actionwoocommerce_rest_checkout_process_payment_with_contextincludes\class\blocks_support_pix.php:21
actionwoocommerce_view_orderincludes\class\boleto.php:37
actionadmin_noticesincludes\class\boleto.php:40
actionwoocommerce_cart_calculate_feesincludes\class\boleto.php:41
actionwoocommerce_checkout_create_orderincludes\class\boleto.php:42
actionwoocommerce_view_orderincludes\class\credit.php:34
actionadmin_noticesincludes\class\credit.php:39
actionwoocommerce_cart_calculate_feesincludes\class\credit.php:40
actionwoocommerce_checkout_create_orderincludes\class\credit.php:41
actionwoocommerce_view_orderincludes\class\pix.php:34
actionadmin_noticesincludes\class\pix.php:39
actionwoocommerce_cart_calculate_feesincludes\class\pix.php:40
actionwoocommerce_checkout_create_orderincludes\class\pix.php:41
actioninitincludes\class\start.php:12
actionwp_enqueue_scriptsincludes\class\start.php:13
actionadmin_enqueue_scriptsincludes\class\start.php:14
filterwoocommerce_checkout_fieldsincludes\class\start.php:15
filterwoocommerce_payment_gatewaysincludes\class\start.php:21
actionwoocommerce_blocks_loadedincludes\class\start.php:22
actionwoocommerce_blocks_payment_method_type_registrationincludes\class\start.php:52
actionwoocommerce_api_acgpfw_updatesincludes\functions.php:5
actionwoocommerce_checkout_update_order_reviewincludes\functions.php:95
actionadd_meta_boxesincludes\functions.php:103
filterwoocommerce_admin_order_titleincludes\functions.php:193
actionmanage_shop_order_posts_custom_columnincludes\functions.php:211
actionmanage_woocommerce_page_wc-orders_custom_columnincludes\functions.php:227
Maintenance & Trust

Global Pays – Payments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 29, 2025
PHP min version7.4
Downloads230

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Global Pays – Payments for WooCommerce Developer Profile

Global Pays

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Global Pays – Payments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/global-pays-payments-for-woocommerce/assets/css/frontend.css/wp-content/plugins/global-pays-payments-for-woocommerce/assets/js/frontend.js
Script Paths
/wp-content/plugins/global-pays-payments-for-woocommerce/assets/js/frontend.js
Version Parameters
global-pays-payments-for-woocommerce/assets/css/frontend.css?ver=global-pays-payments-for-woocommerce/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
acgpfw_boleto-blocks-integration
HTML Comments
╔════════════════════════════════════════════════════════════════════════════════════════╗ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░< DESENVOLVIDO POR />░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ║░░░░██████████║░░░███║░░░░░░░░███║░░░██████║░░░██████║░░░░███████║░░░░██████║░░░███║░░░░║ ║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░██║░░░░░░░██║░░░░░░░██║░░░░██║░░░███║███║░███║░░░░║ ║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░██║░░░░░░░██║░░░░░░░██║░░░░██║░░░███║░███║░███║░░░░║ ║░░░░██████████║░░░███║░░░░░░░░███║░░░██████║░░░██████║░░░██║░░░░██║░░░███║░███║░███║░░░░║ ║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░░░░░██║░░░░░░░██║░░░██║░░░░██║░░░███║░███║░███║░░░░║ ║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░░░░░██║░░░░░░░██║░░░██║░░░░██║░░░███║░███║░███║░░░░║ ║░░░░███║░░░███║░░░████████║░░░███║░░░██████║░░░██████║░░░░███████║░░░░███║░░██████║░░░░░║ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░.:░WWW.DEVALISSON.COM░:.░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║ ╚════════════════════════════════════════════════════════════════════════════════════════╝
Data Attributes
data-plugin-name="Global Pays - Payments for WooCommerce"
JS Globals
acgpfw_BoletoData
REST Endpoints
/wp-json/global-pays-payments-for-woocommerce/v1/settings
FAQ

Frequently Asked Questions about Global Pays – Payments for WooCommerce