
Paga con Bollettino Security & Risk Analysis
wordpress.org/plugins/paga-con-bollettinoGateway to pay with Bollettino Postale
Is Paga con Bollettino Safe to Use in 2026?
Generally Safe
Score 85/100Paga con Bollettino has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "paga-con-bollettino" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. It has a minimal attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these are exposed without authentication checks. The code also demonstrates good practices by exclusively using prepared statements for its SQL queries and not performing any file operations or external HTTP requests. However, a significant concern arises from the low percentage of properly escaped output (38%), indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The absence of nonce and capability checks, while not directly exploitable due to the lack of entry points, represents a missed opportunity for robust security in potential future development.
The vulnerability history for this plugin is clean, with no recorded CVEs. This, combined with the static analysis findings, suggests that the plugin has either been very carefully developed or has not been extensively tested for vulnerabilities. The lack of any taint analysis results, while potentially positive, could also indicate that the analysis performed was limited or that the plugin's code complexity did not trigger any flows for the analysis tool. While the plugin's current footprint is small and appears to lack immediate exploitable vulnerabilities, the unescaped output remains a notable weakness that should be addressed to prevent potential XSS attacks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Paga con Bollettino Security Vulnerabilities
Paga con Bollettino Release Timeline
Paga con Bollettino Code Analysis
Output Escaping
Paga con Bollettino Attack Surface
WordPress Hooks 4
Maintenance & Trust
Paga con Bollettino Maintenance & Trust
Maintenance Signals
Community Trust
Paga con Bollettino Alternatives
Event Organiser Posterboard
event-organiser-posterboard
Adds an 'event board' to display your events in a responsive posterboard.
La Poste Pro Expéditions WooCommerce
la-poste-pro-expeditions-woocommerce
Manage your ecommerce shipments. No subscription, no hidden fees.
Postepay Gateway per Woocommerce
postepay-woocommerce-gateway
Abilita Postapay (o altro sistema di ricarica) come sistema di pagamento per WooCommerce.
Payment Gateway Payoneer For WooCommerce
wc-payoneer-payment-gateway
This is Payoneer Payment Gateway plugin for WooCommerce.
Bring Fraktguiden for WooCommerce
bring-fraktguiden-for-woocommerce
Bring Fraktguiden provides shipping calculation based on rates from bring.no.
Paga con Bollettino Developer Profile
2 plugins · 20 total installs
How We Detect Paga con Bollettino
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/paga-con-bollettino/paga-con-bollettino.phpHTML / DOM Fingerprints
ppay_details<h2>Informazioni di pagamento</h2><ul class="order_details ppay_details"><li>Numero Bollettino Postale: <strong><li>Intestatario Bollettino Postale: <strong>