Payment Integration Wompi Security & Risk Analysis

wordpress.org/plugins/payment-integration-wompi

Integration of Wompi for Woocommerce

1K active installs v4.0.1 PHP 8.0+ WP 6.0+ Updated Aug 6, 2024
commercee-commercestorewordpress-ecommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Payment Integration Wompi Safe to Use in 2026?

Generally Safe

Score 92/100

Payment Integration Wompi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "payment-integration-wompi" v4.0.1 exhibits a generally strong security posture in several key areas. The absence of known CVEs and a clean vulnerability history are positive indicators, suggesting a history of responsible development and maintenance. Static analysis reveals a limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks. The plugin also avoids dangerous functions and only uses prepared statements for its SQL queries. However, there are significant concerns regarding output escaping, with 100% of identified outputs not being properly escaped. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. Additionally, the presence of a file operation without further context is a potential concern, depending on the nature of the operation and whether it's appropriately handled.

Key Concerns

  • Unescaped output detected
  • File operation without context
Vulnerabilities
None known

Payment Integration Wompi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Payment Integration Wompi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Payment Integration Wompi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_noticesincludes\class-woo-wompi-payment-plugin.php:54
filterwoocommerce_payment_gatewaysincludes\class-woo-wompi-payment-plugin.php:66
actionwoocommerce_blocks_loadedincludes\class-woo-wompi-payment-plugin.php:67
actionwoocommerce_blocks_payment_method_type_registrationincludes\class-woo-wompi-payment-plugin.php:86
actionplugins_loadedpayment-integration-wompi.php:23
actionbefore_woocommerce_initpayment-integration-wompi.php:24
actionadmin_noticespayment-integration-wompi.php:64
actionadmin_noticespayment-integration-wompi.php:79
Maintenance & Trust

Payment Integration Wompi Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 6, 2024
PHP min version8.0
Downloads31K

Community Trust

Rating84/100
Number of ratings5
Active installs1K
Developer Profile

Payment Integration Wompi Developer Profile

Saul Morales Pacheco

11 plugins · 8K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Payment Integration Wompi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/payment-integration-wompi/assets/css/wompi.css/wp-content/plugins/payment-integration-wompi/assets/js/wompi.js
Script Paths
/wp-content/plugins/payment-integration-wompi/assets/js/wompi.js
Version Parameters
payment-integration-wompi/assets/css/wompi.css?ver=payment-integration-wompi/assets/js/wompi.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Payment Integration Wompi