PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Security & Risk Analysis

wordpress.org/plugins/paypay-pagamentos-multibanco-e-cartao-de-creditodebito

Aceite pagamentos por Multibanco, Cartão de Crédito/Débito e MB WAY na sua loja WooCommerce de forma segura e instantânea.

10 active installs v2.0.6 PHP 7.2+ WP 4.6+ Updated Mar 13, 2026
credit-cardmbwaymultibancopaymentsvisa
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Safe to Use in 2026?

Generally Safe

Score 100/100

PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

This plugin exhibits a generally positive security posture with no known historical vulnerabilities and a clean static analysis report regarding critical security flaws like unsanitized paths or dangerous functions. The extensive use of prepared statements for SQL queries (96%) and a reasonable rate of output escaping (67%) are strong indicators of secure coding practices. The absence of external HTTP requests and a remarkably small attack surface with zero identified entry points further bolster its security. However, the complete lack of nonce checks and capability checks across all aspects of its operation, combined with the presence of file operations, presents a significant concern. While the static analysis didn't flag specific exploitable issues in these areas, the absence of these fundamental security controls leaves the plugin susceptible to potential privilege escalation, cross-site request forgery (CSRF), or unauthorized file manipulation if any subtle vulnerability exists or is introduced in future updates. The bundling of Guzzle, while not inherently insecure, could pose a risk if an outdated version is used and contains known vulnerabilities, though this is not explicitly stated in the provided data.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • File operations present without specified checks
  • Bundled library (Guzzle) may be outdated
  • Output escaping at 67% is not ideal
Vulnerabilities
None known

PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
22 prepared
Unescaped Output
9
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

96% prepared23 total queries

Output Escaping

67% escaped27 total outputs
Attack Surface

PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionwoocommerce_receipt_paypay_ccsrc\class-paypay.php:84
actionwoocommerce_receipt_paypay_mbsrc\class-paypay.php:85
actionwoocommerce_receipt_paypay_mwsrc\class-paypay.php:86
actionwoocommerce_sections_checkoutsrc\class-paypay.php:690
actionwoocommerce_sections_checkoutsrc\class-paypay.php:710
actionwoocommerce_sections_checkoutsrc\class-paypay.php:729
actionadmin_noticeswoocommerce-paypay.php:40
actionadmin_noticeswoocommerce-paypay.php:51
actionplugins_loadedwoocommerce-paypay.php:75
filterwoocommerce_payment_gatewayswoocommerce-paypay.php:82
filterwoocommerce_available_payment_gatewayswoocommerce-paypay.php:120
actionwoocommerce_api_paypay_webhookwoocommerce-paypay.php:146
actionwoocommerce_api_paypay_cancelwoocommerce-paypay.php:154
actionwoocommerce_email_before_order_tablewoocommerce-paypay.php:165
actionwoocommerce_order_details_after_order_tablewoocommerce-paypay.php:197
filterwoocommerce_valid_order_statuses_for_paymentwoocommerce-paypay.php:225
filterwoocommerce_my_account_my_orders_actionswoocommerce-paypay.php:235
actionupgrader_process_completewoocommerce-paypay.php:252
actionbefore_woocommerce_paywoocommerce-paypay.php:276
actionwp_enqueue_scriptswoocommerce-paypay.php:292
Maintenance & Trust

PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.2
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY Developer Profile

paypayue

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paypay-pagamentos-multibanco-e-cartao-de-creditodebito/assets/css/paypay.css/wp-content/plugins/paypay-pagamentos-multibanco-e-cartao-de-creditodebito/assets/js/paypay.js
Script Paths
/wp-content/plugins/paypay-pagamentos-multibanco-e-cartao-de-creditodebito/assets/js/paypay.js
Version Parameters
paypay-pagamentos-multibanco-e-cartao-de-creditodebito/assets/css/paypay.css?ver=paypay-pagamentos-multibanco-e-cartao-de-creditodebito/assets/js/paypay.js?ver=

HTML / DOM Fingerprints

CSS Classes
paypay-checkout-fieldspaypay-payment-method-icon
HTML Comments
<!-- PAYPAY PAYMENT LOGO AND BUTTON --><!-- PAYPAY CHECKOUT FIELDS -->
Data Attributes
data-paypay-gateway-iddata-paypay-gateway-title
JS Globals
PayPayGatewaySettingspaypay_ajax_object
REST Endpoints
/wp-json/paypay/v1/webhook
FAQ

Frequently Asked Questions about PayPay – Pagamentos Multibanco, Cartão de Crédito/Débito e MB WAY