
MexPago Pasarela de Pago para WC Security & Risk Analysis
wordpress.org/plugins/mexpago-pasarela-de-pago-para-wcHabilitar MexPago como un método de pago directo válido para Woocomerce.
Is MexPago Pasarela de Pago para WC Safe to Use in 2026?
Generally Safe
Score 85/100MexPago Pasarela de Pago para WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mexpago-pasarela-de-pago-para-wc" v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, and the use of prepared statements for all SQL queries are strong indicators of secure coding practices. Furthermore, the taint analysis revealing no unsanitized paths or critical/high severity flows is highly positive.
However, the static analysis does highlight several areas of concern that prevent a perfect score. The complete lack of nonce checks and capability checks across all identified entry points (even though the attack surface is currently zero) represents a significant potential risk. If any entry points were to be added or discovered later, they would be completely unprotected against CSRF attacks and unauthorized access. The relatively low percentage of properly escaped output (83%) also suggests a potential for XSS vulnerabilities, though the taint analysis did not identify any such flows.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the positive taint analysis, suggests that the currently implemented code is likely secure. However, the lack of robust authentication and authorization mechanisms within the existing (albeit small) attack surface is a notable weakness that could be exploited if new vulnerabilities are introduced or if the attack surface expands. The external HTTP requests, while not inherently insecure, represent potential attack vectors if the external services are compromised or if the plugin does not validate responses properly.
Key Concerns
- No nonce checks
- No capability checks
- Incomplete output escaping (17% unescaped)
- External HTTP requests
MexPago Pasarela de Pago para WC Security Vulnerabilities
MexPago Pasarela de Pago para WC Code Analysis
Output Escaping
MexPago Pasarela de Pago para WC Attack Surface
WordPress Hooks 2
Maintenance & Trust
MexPago Pasarela de Pago para WC Maintenance & Trust
Maintenance Signals
Community Trust
MexPago Pasarela de Pago para WC Alternatives
PAYCOMET for WooCommerce
paytpv-for-woocommerce
Módulo de pago PAYCOMET para WooCommerce. Permite realizar pagos con tarjeta de crédito. PAYCOMET - Pasarela de pagos PCI-DSS Nivel 1 Multiplataforma
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
MexPago Pasarela de Pago para WC Developer Profile
1 plugin · 10 total installs
How We Detect MexPago Pasarela de Pago para WC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mexpago-pasarela-de-pago-para-wc/assets/css/mexpago-styles.css/wp-content/plugins/mexpago-pasarela-de-pago-para-wc/assets/js/mexpago-scripts.jsmexpago-pasarela-de-pago-para-wc/assets/css/mexpago-styles.css?ver=mexpago-pasarela-de-pago-para-wc/assets/js/mexpago-scripts.js?ver=HTML / DOM Fingerprints
mexpago-payment-formmexpago-checkout-fields<!-- MexPago Payment Gateway -->data-mexpago-api-keydata-mexpago-modewindow.mexpagoConfigvar mexpago_ajax_url/wp-json/mexpago/v1/payment-callback/wp-json/mexpago/v1/status-update[mexpago_payment_button]