
iPag Pagamentos Digitais Security & Risk Analysis
wordpress.org/plugins/ipag-woocommerceFacilite pagamentos online com segurança e rapidez, integrando sua loja ao nosso gateway e PSP.
Is iPag Pagamentos Digitais Safe to Use in 2026?
Generally Safe
Score 100/100iPag Pagamentos Digitais has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ipag-woocommerce plugin v2.13.2 presents a significant security risk due to a large attack surface comprised entirely of unprotected AJAX handlers. With 3 AJAX entry points identified and none of them including authorization checks, any unauthenticated user could potentially trigger these actions, leading to a broad range of vulnerabilities. The taint analysis also revealed critical flows with unsanitized paths, which, despite not being classified as critical or high severity by the analysis, indicate a strong possibility of injection-type attacks if not properly handled. Furthermore, the plugin exhibits poor output escaping practices, with only 18% of outputs being properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of known CVEs and a clean vulnerability history suggest that the plugin has not been publicly exploited or identified as vulnerable in the past, which is a positive sign. However, the current static analysis findings highlight fundamental security weaknesses that could be exploited even without prior known vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
- No capability checks
iPag Pagamentos Digitais Security Vulnerabilities
iPag Pagamentos Digitais Release Timeline
iPag Pagamentos Digitais Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
iPag Pagamentos Digitais Attack Surface
AJAX Handlers 3
WordPress Hooks 28
Maintenance & Trust
iPag Pagamentos Digitais Maintenance & Trust
Maintenance Signals
Community Trust
iPag Pagamentos Digitais Alternatives
Click2pay para WooCommerce | PIX, Cartão de Crédito e Boleto Bancário
click2pay-pagamentos
Ofereça a seus clientes pagamentos via Pix, assinatura recorrente, cartão de crédito ou boleto bancário, com as melhores tarifas!
Virtuaria PagBank / PagSeguro para Woocommerce
virtuaria-pagseguro
Crédito, Pix e Boleto na sua loja virtual. Mais segurança, menos chargebacks com 3DS. Descontos nas taxas do PagBank.
PagHiper Boleto e PIX para WooCommerce
woo-boleto-paghiper
Ofereça a seus clientes pagamento boleto bancário com a PagHiper. Fácil, prático e rapido!
Virtuaria Rede ( Itaú ) Pagamentos
virtuaria-eredeitau
Pagamentos via Pix e Cartão de Crédito na sua loja virtual com a confiabilidade da Rede / Itaú diretamente em seu WooCommerce.
Pagou – Payments for WooCommerce
pagou-payments-for-woocommerce
Pagamentos via PIX e boletos bancários no WooCommerce.
iPag Pagamentos Digitais Developer Profile
2 plugins · 170 total installs
How We Detect iPag Pagamentos Digitais
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ipag-woocommerce/assets/images/logo.png/wp-content/plugins/ipag-woocommerce/assets/js/ipag-woocommerce-admin.js/wp-content/plugins/ipag-woocommerce/assets/css/ipag-woocommerce-admin.css/wp-content/plugins/ipag-woocommerce/assets/js/ipag-woocommerce.js/wp-content/plugins/ipag-woocommerce/assets/css/ipag-woocommerce.cssipag-woocommerce/assets/js/ipag-woocommerce.js?ver=ipag-woocommerce/assets/css/ipag-woocommerce.css?ver=HTML / DOM Fingerprints
wc_payment_method_ipag-gateway_boletowc_payment_method_wc_gateway_ipag_pixwc_payment_method_wc_gateway_ipag_creditowc_payment_method_wc_gateway_ipag_itaushoplinewc_payment_method_wc_gateway_ipag_debitowc_payment_method_wc_gateway_ipag_cartaoduplodata-order_iddata-trans_iddata-statusdata-payment_datedata-noncewindow.ipag_gateway_capture_noncewindow.ipag_gateway_consult_nonce/wp-json/ipag-woocommerce/v1/capture/wp-json/ipag-woocommerce/v1/consult