ilGhera Carta della Cultura for WooCommerce Security & Risk Analysis

wordpress.org/plugins/ilghera-carta-della-cultura-for-woocommerce

Abilita in WooCommerce il pagamento con Carta della Cultura.

0 active installs v1.0.0 PHP + WP 4.0+ Updated Jan 28, 2026
bonus-culturacarta-della-culturacheckoutpayment-gatewaywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ilGhera Carta della Cultura for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

ilGhera Carta della Cultura for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The ilghera-carta-della-cultura-for-woocommerce plugin v1.0.0 exhibits a generally good security posture, with a clean vulnerability history and no reported CVEs. The static analysis indicates a moderate attack surface, primarily through AJAX handlers, but importantly, all identified entry points appear to have authentication checks, which is a positive sign. The absence of dangerous functions and external HTTP requests further contributes to its security. However, a significant concern arises from the taint analysis, which reveals 3 flows with unsanitized paths. While no critical or high severity issues were identified in these flows, unsanitized paths can still lead to various vulnerabilities if user-supplied data is not properly handled. Furthermore, the output escaping is only 59% proper, suggesting a potential for cross-site scripting (XSS) vulnerabilities in a substantial portion of the plugin's output. The plugin also lacks capability checks on its entry points, which, when combined with potential unsanitized inputs, could lead to privilege escalation or unauthorized actions if not properly mitigated by WordPress's default role capabilities. Despite the lack of historical vulnerabilities, these code-level concerns warrant attention.

Key Concerns

  • Unsanitized paths in taint analysis
  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
None known

ilGhera Carta della Cultura for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ilGhera Carta della Cultura for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
78
110 escaped
Nonce Checks
10
Capability Checks
0
File Operations
11
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

59% escaped188 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
add_cat_callback (includes\class-wccdc-admin.php:177)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ilGhera Carta della Cultura for WooCommerce Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_wccdc-delete-certificateincludes\class-wccdc-admin.php:40
authwp_ajax_wccdc-add-catincludes\class-wccdc-admin.php:41
authwp_ajax_wccdc-sandboxincludes\class-wccdc-admin.php:42
authwp_ajax_wccdc_rescan_isbnincludes\class-wccdc-admin.php:43
authwp_ajax_wccdc_remove_manual_fieldincludes\class-wccdc-admin.php:44
WordPress Hooks 16
actionwp_enqueue_scriptsilghera-carta-della-cultura-for-woocommerce.php:102
actionadmin_enqueue_scriptsilghera-carta-della-cultura-for-woocommerce.php:103
actionplugins_loadedilghera-carta-della-cultura-for-woocommerce.php:106
actionbefore_woocommerce_initilghera-carta-della-cultura-for-woocommerce.php:112
actionadmin_initincludes\class-wccdc-admin.php:36
actionadmin_initincludes\class-wccdc-admin.php:37
actionadmin_initincludes\class-wccdc-admin.php:38
actionadmin_menuincludes\class-wccdc-admin.php:39
actionadmin_noticesincludes\class-wccdc-admin.php:1204
actionadmin_noticesincludes\class-wccdc-admin.php:1236
actionwoocommerce_order_details_after_order_tableincludes\class-wccdc-gateway.php:47
actionwoocommerce_email_after_order_tableincludes\class-wccdc-gateway.php:48
actionwoocommerce_admin_order_data_after_billing_addressincludes\class-wccdc-gateway.php:49
filterwoocommerce_available_payment_gatewaysincludes\class-wccdc-gateway.php:52
filterwoocommerce_payment_gatewaysincludes\class-wccdc.php:28
actionadmin_initincludes\class-wccdc.php:31
Maintenance & Trust

ilGhera Carta della Cultura for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version
Downloads120

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ilGhera Carta della Cultura for WooCommerce Developer Profile

ilGhera

13 plugins · 2K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
150 days
View full developer profile
Detection Fingerprints

How We Detect ilGhera Carta della Cultura for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/css/wc-carta-della-cultura.css/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/css/wc-carta-della-cultura-admin.css/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/wc-carta-della-cultura-admin.js/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.css/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/js/script.js
Script Paths
/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/wc-carta-della-cultura-admin.js/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js/wp-content/plugins/ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/js/script.js
Version Parameters
ilghera-carta-della-cultura-for-woocommerce/css/wc-carta-della-cultura.css?ver=ilghera-carta-della-cultura-for-woocommerce/css/wc-carta-della-cultura-admin.css?ver=ilghera-carta-della-cultura-for-woocommerce/js/wc-carta-della-cultura-admin.js?ver=ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.css?ver=ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js?ver=ilghera-carta-della-cultura-for-woocommerce/js/tzCheckbox/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wccdc-fieldwccdc-categories
HTML Comments
<!-- Script e folgi di stile front-end --><!-- Script e folgi di stile back-end --><!-- Nonce per l'eliminazione del certificato --><!-- Pagina opzioni e gestione certificati -->+5 more
Data Attributes
wccdc-del-cert-noncewccdc-add-cat-noncewccdc-categories
JS Globals
wccdcData
REST Endpoints
/wp-json/wp/v2/product_cat
FAQ

Frequently Asked Questions about ilGhera Carta della Cultura for WooCommerce