MIRATIO – Facturación electrónica Perú Security & Risk Analysis

wordpress.org/plugins/miratio

Ahora puedes emitir comprobantes electrónicos como Boletas y Facturas automáticamente con el plugin de MIRATIO para WooCommerce.

10 active installs v2.6 PHP 7.0+ WP 4.7+ Updated Oct 13, 2022
cpefactura-electronicafacturacionwoocommercewp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MIRATIO – Facturación electrónica Perú Safe to Use in 2026?

Generally Safe

Score 85/100

MIRATIO – Facturación electrónica Perú has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "miratio" v2.6 plugin exhibits a concerning security posture due to several critical oversights in its code. While it appears to have no known historical vulnerabilities and uses prepared statements for its SQL queries, these positives are overshadowed by significant weaknesses in its entry points and data sanitization. The plugin exposes two AJAX handlers without any authentication or capability checks, creating a direct path for attackers to interact with the plugin's functionality without proper authorization. Furthermore, the taint analysis reveals flows with unsanitized paths, indicating that user-supplied input might not be adequately validated or escaped before being processed, which could lead to various injection vulnerabilities. The extremely low percentage of properly escaped output also raises alarms, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks on its AJAX endpoints is another major concern. Despite the absence of recorded CVEs, the identified code signals point to substantial potential risks that could be exploited in the wild.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Low output escaping percentage
  • AJAX handlers without nonce checks
  • External HTTP requests without context
Vulnerabilities
None known

MIRATIO – Facturación electrónica Perú Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MIRATIO – Facturación electrónica Perú Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

24% escaped62 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
miratio_box_cpe_peru_markup (includes\miratio-woocommerce-admin-front.php:164)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

MIRATIO – Facturación electrónica Perú Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_miratio_cpe_peru_getClienteincludes\miratio-lib.php:2
authwp_ajax_miratio_cpe_peru_getClienteincludes\miratio-lib.php:3
WordPress Hooks 24
actionadmin_menuincludes\miratio-admin-settings.php:4
actionadmin_initincludes\miratio-admin-settings.php:48
actionadmin_initincludes\miratio-admin-settings.php:97
actionwp_miratio_update_productsincludes\miratio-lib.php:5
filtercron_schedulesincludes\miratio-lib.php:6
actionadmin_enqueue_scriptsincludes\miratio-woocommerce-admin-front.php:4
filtermanage_edit-shop_order_columnsincludes\miratio-woocommerce-admin-front.php:26
actionmanage_shop_order_posts_custom_columnincludes\miratio-woocommerce-admin-front.php:33
actionwoocommerce_admin_order_data_after_billing_addressincludes\miratio-woocommerce-admin-front.php:48
actionwoocommerce_process_shop_order_metaincludes\miratio-woocommerce-admin-front.php:126
actionadd_meta_boxesincludes\miratio-woocommerce-admin-front.php:155
actionwoocommerce_payment_completeincludes\miratio-woocommerce-admin-front.php:209
actionwoocommerce_order_status_completedincludes\miratio-woocommerce-admin-front.php:223
actionwoocommerce_order_status_processingincludes\miratio-woocommerce-admin-front.php:237
actionwp_enqueue_scriptsincludes\miratio-woocommerce-frontend.php:4
actionwoocommerce_checkout_processincludes\miratio-woocommerce-frontend.php:32
actionwoocommerce_before_order_notesincludes\miratio-woocommerce-frontend.php:86
actionwoocommerce_checkout_update_order_metaincludes\miratio-woocommerce-frontend.php:146
filterwoocommerce_order_details_after_customer_detailsincludes\miratio-woocommerce-frontend.php:178
filterwoocommerce_email_after_order_tableincludes\miratio-woocommerce-frontend.php:222
actioninitmiratio.php:39
actionplugins_loadedmiratio.php:41
actionadmin_noticesmiratio.php:63
actionadmin_noticesmiratio.php:68

Scheduled Events 1

wp_miratio_update_products
Maintenance & Trust

MIRATIO – Facturación electrónica Perú Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 13, 2022
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

MIRATIO – Facturación electrónica Perú Developer Profile

carlod

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MIRATIO – Facturación electrónica Perú

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/miratio/assets/css/miratio.css
Script Paths
/wp-content/plugins/miratio/assets/js/miratio-cpe-checkout-nf.js
Version Parameters
miratio/assets/css/miratio.css?ver=miratio/assets/js/miratio-cpe-checkout-nf.js?ver=

HTML / DOM Fingerprints

CSS Classes
sunat_field
Data Attributes
wooweb_cpe_tipo_documentowooweb_cpe_registrowooweb_cpe_razonsocialwooweb_cpe_domiciliofiscalwooweb_cpe_ubigeo
JS Globals
ajax_miratio_cpe_peru
FAQ

Frequently Asked Questions about MIRATIO – Facturación electrónica Perú