Banco Inter MWP for WooCommerce Security & Risk Analysis

wordpress.org/plugins/mwp-gateway-banco-inter

Plugin gratuito para integração com o Banco Inter para pagamentos via Boleto Bancário e Pix com retorno automático.

50 active installs v1.2 PHP 7.3.0+ WP 4.7+ Updated Jul 17, 2024
banco-intergatewaywoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Banco Inter MWP for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Banco Inter MWP for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The mwp-gateway-banco-inter plugin version 1.2 demonstrates some good security practices, including the use of prepared statements for all SQL queries and a relatively high percentage of properly escaped output. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a commitment to security or a lack of past discovery. However, there are significant concerns regarding its attack surface and authorization checks.

The static analysis reveals a notable risk with the REST API route not having a permission callback. This means that any user, potentially even unauthenticated ones, could interact with this API endpoint, posing a direct security risk. While the total number of entry points is low, this single unprotected route is a critical vulnerability. The taint analysis, although showing limited flows, did identify one flow with an unsanitized path, which could be a vector for certain types of attacks if exploited in conjunction with other weaknesses.

Overall, the plugin's lack of historical vulnerabilities is a positive sign, but the current static analysis highlights immediate and actionable security risks. The single unprotected REST API route is a major concern that needs to be addressed urgently. The presence of a file operation and external HTTP requests, while not inherently insecure, warrant closer inspection in the context of the unsanitized path found in the taint analysis.

Key Concerns

  • REST API route without permission callback
  • Taint flow with unsanitized path
  • 1 unprotected entry point
Vulnerabilities
None known

Banco Inter MWP for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Banco Inter MWP for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
18
50 escaped
Nonce Checks
1
Capability Checks
0
File Operations
25
External Requests
2
Bundled Libraries
1

Bundled Libraries

TCPDF

SQL Query Safety

100% prepared4 total queries

Output Escaping

74% escaped68 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
<index> (gateways\phpqrcode\index.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Banco Inter MWP for WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/inter/v1/webhookinc\webhook.php:4
WordPress Hooks 13
filterwoocommerce_payment_gatewaysgateways\billet.php:2
actionplugins_loadedgateways\billet.php:7
actionwp_enqueue_scriptsgateways\billet.php:26
filterwoocommerce_payment_gatewaysgateways\pix.php:3
actionplugins_loadedgateways\pix.php:8
actionwp_enqueue_scriptsgateways\pix.php:26
actionadmin_menuinc\core.php:2
actionadmin_post_save_mwp_inter_wc_settingsinc\core.php:139
actionadmin_initinc\core.php:140
actionwpinc\cron.php:32
actionmwp_inter_croninc\cron.php:33
actionrest_api_initinc\webhook.php:2
actionwp_enqueue_scriptsinter-mwp.php:37

Scheduled Events 1

mwp_inter_cron
Maintenance & Trust

Banco Inter MWP for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 17, 2024
PHP min version7.3.0
Downloads2K

Community Trust

Rating30/100
Number of ratings2
Active installs50
Developer Profile

Banco Inter MWP for WooCommerce Developer Profile

Mestres do WP

3 plugins · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Banco Inter MWP for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mwp-gateway-banco-inter/assets/css/style.css
Version Parameters
mwp-gateway-banco-inter/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
mwp-inter-thankyoubutton-thankyou-copybutton-thankyou
Data Attributes
id="mwp-inter-billet-thankyou"data-id="mwp-inter-billet-thankyou"
JS Globals
mwp_inter_get_auth_token
Shortcode Output
<section class="mwp-inter-thankyou" id="mwp-inter-billet-thankyou"><div class="content"><h3>Obrigado<p>Sua compra foi efetuada com sucesso e em breve você irá receber mais informações sobre sua encomenda!</p>
FAQ

Frequently Asked Questions about Banco Inter MWP for WooCommerce