
Marvinerp VAT Europeu e NIF Português Security & Risk Analysis
wordpress.org/plugins/marvinerp-eu-vatBem Vindo ao Marvinerp EU Vat
Is Marvinerp VAT Europeu e NIF Português Safe to Use in 2026?
Generally Safe
Score 85/100Marvinerp VAT Europeu e NIF Português has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The marvinerp-eu-vat plugin v1.0 exhibits a generally strong security posture with several good practices observed. The absence of known CVEs and a clean vulnerability history are positive indicators. Furthermore, the code analysis shows a commitment to security by using prepared statements for all SQL queries and properly escaping all output. The limited number of file operations also contributes to a smaller potential attack surface in this regard.
However, there are significant areas of concern stemming from the static analysis. The complete lack of nonce checks and capability checks is a major red flag, especially given the presence of file operations. This means that any functionality involving file operations is potentially accessible to unauthenticated or unauthorized users. While the taint analysis didn't reveal critical or high-severity unsanitized paths, the single unsanitized path flow, coupled with the lack of proper authorization checks on file operations, presents a potential risk that could be exploited if combined with other weaknesses or specific user inputs. The absence of AJAX handlers and REST API routes, while reducing the attack surface in those specific areas, does not mitigate the risks associated with other entry points.
In conclusion, while the plugin demonstrates good practices in data handling (SQL and output), the critical oversight in implementing authorization and nonce checks for file operations creates a substantial security weakness. The vulnerability history offers reassurance, but the current static analysis reveals exploitable gaps that need immediate attention to ensure robust security.
Key Concerns
- Missing nonce checks on file operations
- Missing capability checks on file operations
- Unsanitized path flow detected
Marvinerp VAT Europeu e NIF Português Security Vulnerabilities
Marvinerp VAT Europeu e NIF Português Code Analysis
Output Escaping
Data Flow Analysis
Marvinerp VAT Europeu e NIF Português Attack Surface
WordPress Hooks 7
Maintenance & Trust
Marvinerp VAT Europeu e NIF Português Maintenance & Trust
Maintenance Signals
Community Trust
Marvinerp VAT Europeu e NIF Português Alternatives
NIF (Num. de Contribuinte Português) for WooCommerce
nif-num-de-contribuinte-portugues-for-woocommerce
This plugin adds the Portuguese NIF/NIPC as a new field to WooCommerce checkout and order details, if the billing address / customer is from Portugal.
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
wp-optimize
Get caching and more with this powerful cache plugin. Cache, optimize images, clean your database and minify for maximum performance.
SpeedyCache – Cache, Optimization, Performance
speedycache
SpeedyCache is a WordPress cache plugin that helps you improve performance of your WordPress site by caching, minifying, and compressing your website.
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Marvinerp VAT Europeu e NIF Português Developer Profile
3 plugins · 10 total installs
How We Detect Marvinerp VAT Europeu e NIF Português
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/marvinerp-eu-vat/assets/bootstrap.min.css/wp-content/plugins/marvinerp-eu-vat/assets/bootstrap.min.css.map/wp-content/plugins/marvinerp-eu-vat/assets/style.cssmarvinerp-eu-vat/assets/bootstrap.min.css?ver=marvinerp-eu-vat/assets/bootstrap.min.css.map?ver=marvinerp-eu-vat/assets/style.css?ver=HTML / DOM Fingerprints
id="VAT_Settings"MVPN_NIF_ON<tr>
<th><b>European ID VAT Number - (Portugal: NIF) </b>:</th>
<td>