
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Security & Risk Analysis
wordpress.org/plugins/multibanco-e-ou-payshop-by-lusopayWooCommerce plugin for MULTIBANCO, PAYSHOP, MB Way and Cofidis Pay. It allows to send SMS and e-mail to the customer with payment details.
Is Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "multibanco-e-ou-payshop-by-lusopay" plugin, version 5.0.0, exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, critical or high-severity taint flows, and a good percentage of SQL queries utilizing prepared statements are positive indicators. Furthermore, the plugin does not appear to have a large attack surface exposed without authentication, with zero unprotected AJAX handlers, REST API routes, shortcodes, or cron events identified.
However, there are areas for improvement. A significant concern is the relatively low percentage of properly escaped outputs (75%), suggesting a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled meticulously in the remaining 25% of outputs. The plugin also performs nine external HTTP requests, which, while not inherently insecure, can become a vector for vulnerabilities if the target endpoints are compromised or if data is transmitted insecurely. The single nonce check is also a point of attention, as robust nonce usage is crucial for preventing CSRF attacks, especially if any backend functionality is triggered by front-end interactions.
In conclusion, while the plugin benefits from a lack of critical known vulnerabilities and a seemingly controlled attack surface, the moderate output escaping and external HTTP requests warrant careful review and potential hardening. The plugin's clean vulnerability history is a strength, but vigilance against the identified code signals is recommended to maintain a secure state.
Key Concerns
- Output escaping is not consistently applied (75%)
- 9 external HTTP requests made by the plugin
- Only 1 nonce check present
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Security Vulnerabilities
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Attack Surface
WordPress Hooks 46
Maintenance & Trust
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Alternatives
easypay Gateway Checkout for WooCommerce
easypay-gateway-checkout-wc
Plugin para aceitar pagamentos via Multibanco, MBWay, Visa e Mastercard, Débitos Diretos, Santander Consumer, Universo Flex, IBAN Digital e Apple Pay.
PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY
paypay-pagamentos-multibanco-e-cartao-de-creditodebito
Aceite pagamentos por Multibanco, Cartão de Crédito/Débito e MB WAY na sua loja WooCommerce de forma segura e instantânea.
Payshop Online Payments
payshop-online-payments
Accept MB WAY, Multibanco Reference, Credit Card, Google Pay, and Payshop Reference – With Payshop Online Payments (POP) – for Woocommerce
Breadcrumbs for WooCommerce
woocommerce-breadcrumbs
A simple plugin to style the WooCommerce Breadcrumbs or disable them altogether
Delivery Mail Boxes Etc. for WooCommerce
delivery-mail-boxes-etc-for-woocommerce
Плагин создает накладные в системе Mail Boxes Etc. для сайтов на WooCommerce.
Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce Developer Profile
1 plugin · 400 total installs
How We Detect Multibanco / MB Way / Payshop / Cofidis Pay (by LUSOPAY) for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/css/lusopay-style.css/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-script.js/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-admin-script.js/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-checkout-script.js/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/includes/assets/css/lusopay-admin-style.css/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-script.js/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-admin-script.js/wp-content/plugins/multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-checkout-script.jsmultibanco-e-ou-payshop-by-lusopay/assets/css/lusopay-style.css?ver=multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-script.js?ver=multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-admin-script.js?ver=multibanco-e-ou-payshop-by-lusopay/assets/js/lusopay-checkout-script.js?ver=multibanco-e-ou-payshop-by-lusopay/includes/assets/css/lusopay-admin-style.css?ver=HTML / DOM Fingerprints
lusopay-gateway-wrapperlusopay-terms-sectionlusopay-admin-noticelusopay-checkout-field<!-- Renderiza a página de configurações da LusoPay (usando o template do WooCommerce) --><!-- Lusopay Plugin Version --><!-- Instance of this class. --><!-- Load plugin text domain -->+20 moredata-lusopay-terms-accepteddata-lusopay-settings-pagewindow.lusopay_ajax_objectvar lusopay_admin_params/wp-json/lusopay/v1/settings[lusopay_payment_form]