Perseo Software Security & Risk Analysis

wordpress.org/plugins/perseo-software

Integra el Sistema Contable Perseo (Web y PC) con tu tienda WooCommerce. Sincroniza productos, clientes, inventario y pedidos automáticamente.

10 active installs v33.0 PHP 7.4+ WP 5.0+ Updated Jan 14, 2026
erpinventoryperseosyncwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Perseo Software Safe to Use in 2026?

Generally Safe

Score 100/100

Perseo Software has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "perseo-software" plugin v33.0 exhibits a mixed security posture. On the positive side, it has a minimal attack surface with no exposed AJAX handlers or REST API routes lacking authentication. The plugin also demonstrates good practices with a high percentage of SQL queries using prepared statements and a majority of output being properly escaped. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history is a significant strength, suggesting a history of responsible development.

However, the presence of a dangerous `unserialize` function is a notable concern, even if current taint analysis did not flag it as critical or high *without sanitization*. A single unsanitized path identified in the taint analysis, even at a lower severity, warrants attention as it could potentially be chained with other factors or become exploitable in future code changes. The single file operation and external HTTP requests, while not inherently problematic, could be vectors if not handled securely. The limited number of nonce and capability checks suggests a potential for privilege escalation or unauthorized actions if the `unserialize` function or the unsanitized path were to be misused.

In conclusion, while the plugin benefits from a clean vulnerability history and a controlled attack surface, the presence of `unserialize` and an identified unsanitized path represent potential weak points. Developers should prioritize a thorough review and sanitization of data processed by `unserialize` and the identified unsanitized path to mitigate risks.

Key Concerns

  • Dangerous function: unserialize
  • Flows with unsanitized paths: 1 (High severity taint)
Vulnerabilities
None known

Perseo Software Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Perseo Software Release Timeline

v25.0
v24.0
v23.0
v22.0
v21.0
v20.0
v18.0
v17.0
v16.0
v15.0
v14.0
v13.0
v12.0
v11.0
v10.0
v9.0
v8.0
v7.0
v6.0
v5.0
Code Analysis
Analyzed Mar 16, 2026

Perseo Software Code Analysis

Dangerous Functions
1
Raw SQL Queries
17
14 prepared
Unescaped Output
22
62 escaped
Nonce Checks
2
Capability Checks
6
File Operations
1
External Requests
14
Bundled Libraries
0

Dangerous Functions Found

unserialize$perseo_CodProdP = isset($detalle->attributes) ? unserialize($detalle->attributes) : [];includes\PluginPerseo_cron.php:318

SQL Query Safety

45% prepared31 total queries

Output Escaping

74% escaped84 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

5 flows1 with unsanitized paths
sperseo_seccionencabezado (PluginPerseo.php:478)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Perseo Software Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actioncron_schedulesincludes\PluginPerseo_master.php:38
actionperseo_cronincludes\PluginPerseo_master.php:39
actionperseo_cronincludes\PluginPerseo_master.php:40
actionperseo_cronincludes\PluginPerseo_master.php:41
actionperseo_cronincludes\PluginPerseo_master.php:42
actionperseo_cronincludes\PluginPerseo_master.php:43
actionperseo_cronincludes\PluginPerseo_master.php:44
actioninitincludes\PluginPerseo_master.php:45
actionupdate_option_pluginperseo_parametrosincludes\PluginPerseo_master.php:48
actionadmin_post_perseo_limpiar_transientsPluginPerseo.php:101
actionplugins_loadedPluginPerseo.php:123
actionwp_headPluginPerseo.php:128
actionadmin_menuPluginPerseo.php:141
actionadmin_initPluginPerseo.php:476
actionadmin_enqueue_scriptsPluginPerseo.php:998
actionwoocommerce_register_formPluginPerseoClientes.php:29
filterwoocommerce_registration_errorsPluginPerseoClientes.php:59
actionuser_registerPluginPerseoClientes.php:78
actionshow_user_profilePluginPerseoClientes.php:83
actionedit_user_profilePluginPerseoClientes.php:84
actionpersonal_options_updatePluginPerseoClientes.php:123
actionedit_user_profile_updatePluginPerseoClientes.php:124

Scheduled Events 1

perseo_cron
Maintenance & Trust

Perseo Software Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 14, 2026
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Perseo Software Developer Profile

perseosoftware

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Perseo Software

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/perseo-software/css/pluginperseo.css/wp-content/plugins/perseo-software/js/pluginperseo.js
Script Paths
/wp-content/plugins/perseo-software/js/pluginperseo.js
Version Parameters
pluginperseo.css?ver=pluginperseo.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="perseoconexion"onclick="perseotestconec()"
JS Globals
var perseotestconec = function() {window.perseotestconec = function() {
FAQ

Frequently Asked Questions about Perseo Software