
PagTur for WooCommerce Security & Risk Analysis
wordpress.org/plugins/pagtur-woocommercePagTur Payment Plugin for WooCommerce
Is PagTur for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100PagTur for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pagtur-woocommerce" plugin v1.1 exhibits a strong security posture in several key areas. Its static analysis reveals no identifiable attack surface through AJAX handlers, REST API, shortcodes, or cron events. Furthermore, all SQL queries are executed using prepared statements, which is a significant safeguard against SQL injection. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, the most glaring concern is the extremely low percentage of properly escaped output (11%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly in the browser without adequate sanitization. The complete lack of nonce checks and capability checks, coupled with no recorded vulnerability history, suggests that while the plugin may not have known exploits or a history of insecure coding in these specific areas, it relies on the WordPress core for security, which is not always sufficient for plugin-specific functionalities that might be exposed in the future or through the unescaped output. The plugin's strengths lie in its handling of database queries and limited attack surface, but the output escaping deficiency presents a critical and immediate risk.
Key Concerns
- Low percentage of properly escaped output
- Zero nonce checks
- Zero capability checks
PagTur for WooCommerce Security Vulnerabilities
PagTur for WooCommerce Release Timeline
PagTur for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
PagTur for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
PagTur for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PagTur for WooCommerce Alternatives
ParceladoUSA Payment Gateway for WooCommerce
parceladousa-payment-gateway-for-woocommerce
Accept payments from Brazilians in your store through ParceladoUSA with installment options.
Depix – PIX Payment Gateway for WooCommerce
depix-gateway
Native PIX payment gateway for WooCommerce. No monthly fees and no chargeback risk after settlement.
Brazilian Market on WooCommerce
woocommerce-extra-checkout-fields-for-brazil
Adds Brazilian checkout fields in WooCommerce
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
PagTur for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect PagTur for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pagtur-woocommerce/assets/images/pagturcards-175x29.png/wp-content/plugins/pagtur-woocommerce/includes/lib/vendor/autoload.php/wp-content/plugins/pagtur-woocommerce/includes/controllers/WC_PAGTUR_API.php/wp-content/plugins/pagtur-woocommerce/includes/controllers/WC_PAGTUR_DB.php/wp-content/plugins/pagtur-woocommerce/includes/models/pagtur_basemodel.php/wp-content/plugins/pagtur-woocommerce/includes/models/Response/GetTokenResponse.php/wp-content/plugins/pagtur-woocommerce/includes/models/Response/GetInstallmentsResponse.php+2 moreHTML / DOM Fingerprints
pagtur_formpagtur_creditcardpagtur_expiration_datepagtur_cvvpagtur_numberpagtur_cardholderpagtur_form-grouppagtur_form-control+1 more<!-- PagTur for WooCommerce Settings --><!-- TravelAgency Title --><!-- TravelAgency_Name --><!-- TravelAgency_Email -->+9 moredata-pagtur-usernamedata-pagtur-passworddata-pagtur-companyNamedata-pagtur-sandboxdata-pagtur-currencyListdata-pagtur-softDescriptor+5 morewindow.pagtur_public_keywindow.pagtur_api_urlwindow.pagtur_payment_methodwindow.pagtur_installmentswindow.pagtur_amountwindow.pagtur_order_id/wp-json/pagtur/v1/installments/wp-json/pagtur/v1/currency