
Global Pays – Payments for WooCommerce Security & Risk Analysis
wordpress.org/plugins/global-pays-payments-for-woocommercePIX, Boleto and credit card payments in WooCommerce.
Is Global Pays – Payments for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Global Pays – Payments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "global-pays-payments-for-woocommerce" plugin, version 1.0.5, exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and achieving a high rate of output escaping (89%). The absence of any recorded vulnerabilities or CVEs in its history is also a strong indicator of diligent security development. However, significant concerns arise from the attack surface analysis. All six identified AJAX handlers lack authentication checks, presenting a direct pathway for unauthorized access and potential manipulation of plugin functionalities. The lack of taint analysis data means we cannot definitively rule out unsanitized input vulnerabilities, though the absence of critical or high severity flows in the limited analysis is a positive sign.
Despite the strong foundation in SQL handling and output sanitization, the unprotected AJAX endpoints represent a critical weakness. This means an attacker could potentially trigger these functions without any verification of user privileges. While no historical vulnerabilities are recorded, this does not guarantee future safety, especially given the exposed attack surface. The plugin would benefit greatly from implementing capability checks on all its AJAX handlers to mitigate the identified risks.
Key Concerns
- Unprotected AJAX handlers
- Limited taint analysis coverage
- No capability checks on AJAX
Global Pays – Payments for WooCommerce Security Vulnerabilities
Global Pays – Payments for WooCommerce Code Analysis
Output Escaping
Global Pays – Payments for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 30
Maintenance & Trust
Global Pays – Payments for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Global Pays – Payments for WooCommerce Alternatives
Pagou – Payments for WooCommerce
pagou-payments-for-woocommerce
Pagamentos via PIX e boletos bancários no WooCommerce.
iPag Pagamentos Digitais
ipag-woocommerce
Facilite pagamentos online com segurança e rapidez, integrando sua loja ao nosso gateway e PSP.
Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário
click2pay-pagamentos
Ofereça a seus clientes pagamentos via Pix, assinatura recorrente, cartão de crédito ou boleto bancário, com as melhores tarifas!
Adicionar Banco Inter ao WooCommerce
wc-banco-inter
Adiciona o Banco Inter como método de pagamento ao seu WooCommerce.
PEI Digital – PIX Sandbox Gateway
pei-digital-sandbox-for-pix
Gateway PIX em sandbox para WooCommerce: simule pagamentos, QR Code e status.
Global Pays – Payments for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect Global Pays – Payments for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/global-pays-payments-for-woocommerce/assets/css/frontend.css/wp-content/plugins/global-pays-payments-for-woocommerce/assets/js/frontend.js/wp-content/plugins/global-pays-payments-for-woocommerce/assets/js/frontend.jsglobal-pays-payments-for-woocommerce/assets/css/frontend.css?ver=global-pays-payments-for-woocommerce/assets/js/frontend.js?ver=HTML / DOM Fingerprints
acgpfw_boleto-blocks-integration╔════════════════════════════════════════════════════════════════════════════════════════╗
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░< DESENVOLVIDO POR />░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
║░░░░██████████║░░░███║░░░░░░░░███║░░░██████║░░░██████║░░░░███████║░░░░██████║░░░███║░░░░║
║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░██║░░░░░░░██║░░░░░░░██║░░░░██║░░░███║███║░███║░░░░║
║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░██║░░░░░░░██║░░░░░░░██║░░░░██║░░░███║░███║░███║░░░░║
║░░░░██████████║░░░███║░░░░░░░░███║░░░██████║░░░██████║░░░██║░░░░██║░░░███║░███║░███║░░░░║
║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░░░░░██║░░░░░░░██║░░░██║░░░░██║░░░███║░███║░███║░░░░║
║░░░░███║░░░███║░░░███║░░░░░░░░███║░░░░░░░██║░░░░░░░██║░░░██║░░░░██║░░░███║░███║░███║░░░░║
║░░░░███║░░░███║░░░████████║░░░███║░░░██████║░░░██████║░░░░███████║░░░░███║░░██████║░░░░░║
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░.:░WWW.DEVALISSON.COM░:.░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
║░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░║
╚════════════════════════════════════════════════════════════════════════════════════════╝data-plugin-name="Global Pays - Payments for WooCommerce"acgpfw_BoletoData/wp-json/global-pays-payments-for-woocommerce/v1/settings