
OurivesWeb Api Security & Risk Analysis
wordpress.org/plugins/ourivesweb-apiO Ourives Web é um produto com a qualidade da PONTO 25 – informática lda.
Is OurivesWeb Api Safe to Use in 2026?
Generally Safe
Score 100/100OurivesWeb Api has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ouivresweb-api plugin version 1.1.1 demonstrates a generally strong security posture with some notable areas for improvement. The plugin excels in limiting its attack surface, with no unprotected AJAX handlers, REST API routes, or shortcodes. Its extensive use of prepared statements for SQL queries (92%) and proper output escaping (75%) are positive indicators of secure coding practices. Furthermore, the absence of any recorded vulnerabilities or CVEs suggests a history of reliable security.
However, the analysis does reveal potential weaknesses. The presence of a single cron event without explicit mention of authentication checks raises a flag. More significantly, a taint analysis identified one flow with an unsanitized path. While no critical or high severity issues were detected in the taint analysis, this indicates a potential for path traversal or similar vulnerabilities if not handled carefully. The plugin also lacks nonce checks on any entry points, which is a common security control for WordPress plugins. The limited number of capability checks (2) alongside the cron event and unsanitized path could potentially allow unauthorized access or execution if combined with other weaknesses or misconfigurations.
In conclusion, ouivresweb-api v1.1.1 is a relatively secure plugin, particularly in its handling of database interactions and output. Its clean vulnerability history is a significant strength. Nevertheless, the identified unsanitized path flow and the absence of nonce checks warrant attention to prevent potential security incidents, especially concerning the cron event's security.
Key Concerns
- Unsanitized path flow detected
- No nonce checks on entry points
- Potential risk with cron event security
- Output escaping is not fully robust (25% not properly escaped)
OurivesWeb Api Security Vulnerabilities
OurivesWeb Api Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
OurivesWeb Api Attack Surface
WordPress Hooks 12
Scheduled Events 1
Maintenance & Trust
OurivesWeb Api Maintenance & Trust
Maintenance Signals
Community Trust
OurivesWeb Api Alternatives
Marvinerp
marvinerp-api
O Marvin ERP é um produto com a qualidade da PONTO 25 – informática lda.
Moloni
moloni
Software de faturação inovador que se adapta ao seu negócio! Destinado a profissionais liberais, micro, pequenas e médias empresas.
Contribuinte Checkout
contribuinte-checkout
With this plugin you can add VAT and VIES support to your WooCommerce store. The VAT field will be saved as '_billing_vat'.
Vendus
vendus
Faturação 100% online, sem dores de cabeça e sem sair da sua loja online! Programa nº 2230 certificado pela AT a partir de 4€ / mês.
Moloni España
moloni-es
Innovative billing software that fits your business.! Intended for professionals, micro, small and medium enterprises.
OurivesWeb Api Developer Profile
3 plugins · 10 total installs
How We Detect OurivesWeb Api
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ourivesweb-api/assets/css/Error.css/wp-content/plugins/ourivesweb-api/assets/Includes/sweetalert2.all.min.js/wp-content/plugins/ourivesweb-api/assets/Includes/sweetalert2.all.min.jsourivesweb-api/assets/css/Error.css?ver=ourivesweb-api/assets/Includes/sweetalert2.all.min.js?ver=HTML / DOM Fingerprints
Swal