Mojito Sinpe Security & Risk Analysis

wordpress.org/plugins/mojito-sinpe

Sinpe Móvil as Woocommerce gateway

300 active installs v1.2.0 PHP 8.1+ WP 5.2+ Updated Jan 10, 2025
ecommercepaymentwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mojito Sinpe Safe to Use in 2026?

Generally Safe

Score 92/100

Mojito Sinpe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "mojito-sinpe" v1.2.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, making all SQL queries via prepared statements, and performing file operations or external HTTP requests. The presence of nonce checks and a relatively low number of output escapement issues are also encouraging. However, significant concerns arise from its attack surface. The plugin exposes one REST API route without any permission callbacks, creating a direct entry point for potential unauthorized access or manipulation. Furthermore, the taint analysis revealed two flows with unsanitized paths, which could lead to vulnerabilities if data from these paths is improperly handled, even if no critical or high severity issues were explicitly flagged in this analysis. The lack of any recorded vulnerability history is positive but does not negate the immediate risks identified in the static analysis.

Key Concerns

  • REST API route without permission callback
  • Flows with unsanitized paths
  • Low percentage of properly escaped output
Vulnerabilities
None known

Mojito Sinpe Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mojito Sinpe Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
20 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped34 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
payment_link (includes\class-mojito-sinpe.php:195)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Mojito Sinpe Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/mojito-sinpe/v1/open-payment-link/includes\class-mojito-sinpe.php:142
WordPress Hooks 17
actioninitincludes\class-mojito-compatibility-product-vendors.php:69
actionwcpv_registration_formincludes\class-mojito-compatibility-product-vendors.php:76
actionwcpv_shortcode_registration_form_processincludes\class-mojito-compatibility-product-vendors.php:77
actionwoocommerce_thankyou_mojito-sinpeincludes\class-mojito-sinpe-gateway.php:83
actionwoocommerce_email_before_order_tableincludes\class-mojito-sinpe-gateway.php:86
filterwoocommerce_payment_gatewaysincludes\class-mojito-sinpe.php:96
actionplugins_loadedincludes\class-mojito-sinpe.php:107
actionwoocommerce_checkout_update_order_metaincludes\class-mojito-sinpe.php:124
actionwoocommerce_email_before_order_tableincludes\class-mojito-sinpe.php:129
actionwoocommerce_thankyouincludes\class-mojito-sinpe.php:134
actionrest_api_initincludes\class-mojito-sinpe.php:139
actionwoocommerce_initincludes\class-mojito-sinpe.php:154
filterwoocommerce_available_payment_gatewaysincludes\class-mojito-sinpe.php:157
actionplugins_loadedincludes\class-mojito-sinpe.php:603
actionwp_enqueue_scriptsincludes\class-mojito-sinpe.php:629
actionwp_enqueue_scriptsincludes\class-mojito-sinpe.php:630
actionbefore_woocommerce_initmojito-sinpe.php:135
Maintenance & Trust

Mojito Sinpe Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 10, 2025
PHP min version8.1
Downloads6K

Community Trust

Rating100/100
Number of ratings6
Active installs300
Developer Profile

Mojito Sinpe Developer Profile

quantumdev

2 plugins · 390 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mojito Sinpe

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mojito-sinpe/assets/css/mojito-sinpe-admin.css/wp-content/plugins/mojito-sinpe/assets/css/mojito-sinpe-public.css/wp-content/plugins/mojito-sinpe/assets/js/mojito-sinpe-admin.js/wp-content/plugins/mojito-sinpe/assets/js/mojito-sinpe-public.js
Script Paths
/wp-content/plugins/mojito-sinpe/assets/js/mojito-sinpe-public.js
Version Parameters
mojito-sinpe/assets/css/mojito-sinpe-admin.css?ver=mojito-sinpe/assets/css/mojito-sinpe-public.css?ver=mojito-sinpe/assets/js/mojito-sinpe-admin.js?ver=mojito-sinpe/assets/js/mojito-sinpe-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
mojito-sinpe-gateway-form
JS Globals
window.mojito_sinpe_public_params
REST Endpoints
/wp-json/mojito-sinpe/v1/open-payment-link/
FAQ

Frequently Asked Questions about Mojito Sinpe