
PagBank / PagSeguro Connect para WooCommerce Security & Risk Analysis
wordpress.org/plugins/pagbank-connectPagBank com PIX, Cartão de Crédito, Boleto, Recorrência + Envio Fácil e com Menos Taxas no PagSeguro. Autenticação 3D: menos chargeback + aprovações.
Is PagBank / PagSeguro Connect para WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100PagBank / PagSeguro Connect para WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "pagbank-connect" v4.53.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling and output escaping, with a high percentage of prepared statements and properly escaped outputs. The absence of dangerous functions and bundled libraries further contributes to its strengths. However, significant concerns arise from the substantial attack surface, particularly the high number of unprotected AJAX handlers and REST API routes. The taint analysis reveals critical security risks with a notable number of flows with unsanitized paths, specifically six high-severity flows, which are deeply concerning as they indicate potential avenues for attackers to manipulate application logic or data. The plugin's vulnerability history, while showing no currently unpatched CVEs, does include a past medium-severity SQL injection vulnerability, suggesting a potential recurring weakness or an area that requires continuous vigilance.
Overall, while the plugin has implemented some robust security measures, the presence of numerous unprotected entry points and the critical findings from the taint analysis present a considerable risk. The high number of unprotected AJAX handlers (6 out of 8) and a REST API route lacking permission callbacks (1 out of 1) are direct vulnerabilities waiting to be exploited. Coupled with the high-severity unsanitized taint flows, these weaknesses can lead to serious security breaches. The plugin's future security hinges on addressing these exposed entry points and thoroughly sanitizing all data flows identified in the taint analysis. Continuous monitoring and prompt patching of any future vulnerabilities are essential.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- High severity unsanitized taint flows
- Past medium severity SQL Injection
PagBank / PagSeguro Connect para WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PagBank / PagSeguro Connect para WooCommerce <= 4.44.3 - Authenticated (Shop Manager+) SQL Injection
PagBank / PagSeguro Connect para WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PagBank / PagSeguro Connect para WooCommerce Attack Surface
AJAX Handlers 8
REST API Routes 1
Shortcodes 1
WordPress Hooks 132
Scheduled Events 5
Maintenance & Trust
PagBank / PagSeguro Connect para WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PagBank / PagSeguro Connect para WooCommerce Alternatives
PagBank for WooCommerce
pagbank-for-woocommerce
Aceite pagamentos via cartão de crédito, boleto e Pix no checkout do WooCommerce através do PagBank.
Virtuaria PagBank / PagSeguro para Woocommerce
virtuaria-pagseguro
Crédito, Pix e Boleto na sua loja virtual. Mais segurança, menos chargebacks com 3DS. Descontos nas taxas do PagBank.
Pix for WooCommerce
payment-gateway-pix-for-woocommerce
Easily accept Pix payments in your WooCommerce store via Pix Key, PagHiper, or C6 Bank. The complete Pix solution for Brazil.
Virtuaria PagBank Split
virtuaria-pagbank-split
Monte facilmente um marketplace, dropshipping ou similar com este plugin. Split de Pagamento, Gestão de Sellers / Comissões e Relatórios
Pinterest for WooCommerce
pinterest-for-woocommerce
Get your products in front of Pinterest users searching for ideas and things to buy. Connect your WooCommerce store to make your catalog browsable.
PagBank / PagSeguro Connect para WooCommerce Developer Profile
2 plugins · 5K total installs
How We Detect PagBank / PagSeguro Connect para WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pagbank-connect/admin/assets/css/integrations.css/wp-content/plugins/pagbank-connect/admin/assets/js/integrations.js/wp-content/plugins/pagbank-connect/admin/assets/js/integrations.jsHTML / DOM Fingerprints
pagbank-connect-integrations-page<!-- Integrations settings page -->data-wp-on--click