
NIF (Num. de Contribuinte Português) for WooCommerce Security & Risk Analysis
wordpress.org/plugins/nif-num-de-contribuinte-portugues-for-woocommerceThis plugin adds the Portuguese NIF/NIPC as a new field to WooCommerce checkout and order details, if the billing address / customer is from Portugal.
Is NIF (Num. de Contribuinte Português) for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100NIF (Num. de Contribuinte Português) for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "nif-num-de-contribuinte-portugues-for-woocommerce" v6.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. The absence of file operations, external HTTP requests, and known vulnerabilities in its history are also strong indicators of a well-maintained and secure codebase. However, a significant concern arises from its attack surface. The presence of one AJAX handler without authentication checks represents a direct entry point that could be exploited by unauthenticated users. The lack of nonce checks for this handler further exacerbates this risk, as it opens the door to potential Cross-Site Request Forgery (CSRF) attacks. While taint analysis revealed no immediate issues, the unprotected AJAX endpoint is a critical oversight that needs immediate attention. Overall, while the core data handling appears secure, the unprotected AJAX endpoint presents a notable weakness.
Key Concerns
- Unprotected AJAX handler
- Missing nonce check on AJAX handler
NIF (Num. de Contribuinte Português) for WooCommerce Security Vulnerabilities
NIF (Num. de Contribuinte Português) for WooCommerce Code Analysis
Output Escaping
NIF (Num. de Contribuinte Português) for WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 31
Maintenance & Trust
NIF (Num. de Contribuinte Português) for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
NIF (Num. de Contribuinte Português) for WooCommerce Alternatives
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
EU/UK VAT Validation Manager for WooCommerce
eu-vat-for-woocommerce
Manage EU/ UK VAT in WooCommerce, validate VAT numbers real time with VIES, exempt or preserve VAT with various settings & cases.
EU VAT Assistant for WooCommerce
woocommerce-eu-vat-assistant
Extends the standard WooCommerce sale process and assists in achieving compliance with the new EU VAT regime starting on the 1st of January 2015.
Tax Switch for WooCommerce
tax-switch-for-woocommerce
Let customers toggle between inclusive and exclusive VAT pricing in your WooCommerce store.
Tax Exemption for WooCommerce
tax-exemption-woo
Tax Exemption plugin for WooCommerce. Allow customers to declare tax / VAT exemption eligibility, and provide tax exemption details.
NIF (Num. de Contribuinte Português) for WooCommerce Developer Profile
21 plugins · 27K total installs
How We Detect NIF (Num. de Contribuinte Português) for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nif-num-de-contribuinte-portugues-for-woocommerce/js/functions.jsjs/functions.jsnif-num-de-contribuinte-portugues-for-woocommerce/js/functions.js?ver=HTML / DOM Fingerprints
woocommerce_nif_infowoocommerce_nif_info_labelwoocommerce_nif_info_valuebilling_nifwoocommerce_nif