Paga con Bollettino Security & Risk Analysis

wordpress.org/plugins/paga-con-bollettino

Gateway to pay with Bollettino Postale

20 active installs v1.0 PHP + WP 3.0.1+ Updated Sep 20, 2016
bollettinobollettino-postalepay-withpostewoocommerce-gateway
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paga con Bollettino Safe to Use in 2026?

Generally Safe

Score 85/100

Paga con Bollettino has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "paga-con-bollettino" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. It has a minimal attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these are exposed without authentication checks. The code also demonstrates good practices by exclusively using prepared statements for its SQL queries and not performing any file operations or external HTTP requests. However, a significant concern arises from the low percentage of properly escaped output (38%), indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The absence of nonce and capability checks, while not directly exploitable due to the lack of entry points, represents a missed opportunity for robust security in potential future development.

The vulnerability history for this plugin is clean, with no recorded CVEs. This, combined with the static analysis findings, suggests that the plugin has either been very carefully developed or has not been extensively tested for vulnerabilities. The lack of any taint analysis results, while potentially positive, could also indicate that the analysis performed was limited or that the plugin's code complexity did not trigger any flows for the analysis tool. While the plugin's current footprint is small and appears to lack immediate exploitable vulnerabilities, the unescaped output remains a notable weakness that should be addressed to prevent potential XSS attacks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Paga con Bollettino Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Paga con Bollettino Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Paga con Bollettino Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

Paga con Bollettino Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedpaga-con-bolletino.php:11
actionwoocommerce_thankyou_ppaypaga-con-bolletino.php:37
actionwoocommerce_email_before_order_tablepaga-con-bolletino.php:40
filterwoocommerce_payment_gatewayspaga-con-bolletino.php:195
Maintenance & Trust

Paga con Bollettino Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedSep 20, 2016
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Paga con Bollettino Developer Profile

caygri

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paga con Bollettino

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paga-con-bollettino/paga-con-bollettino.php

HTML / DOM Fingerprints

CSS Classes
ppay_details
Shortcode Output
<h2>Informazioni di pagamento</h2><ul class="order_details ppay_details"><li>Numero Bollettino Postale: <strong><li>Intestatario Bollettino Postale: <strong>
FAQ

Frequently Asked Questions about Paga con Bollettino