Promociones Mercado Pago Security & Risk Analysis

wordpress.org/plugins/promociones-mercado-pago

Lists Mercado Pago credit and debit card active promotions.

10 active installs v0.1 PHP 5.6+ WP 3.5+ Updated Mar 12, 2018
mercado-pagomercadopagopromocionestarjetas-de-creditotokio-agency
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Promociones Mercado Pago Safe to Use in 2026?

Generally Safe

Score 85/100

Promociones Mercado Pago has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'promociones-mercado-pago' v0.1 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) associated with this plugin, and its code signals indicate the absence of dangerous functions and SQL queries that are not properly prepared. Furthermore, the plugin uses capability checks for some operations and performs file operations and external HTTP requests in a controlled manner.

However, several areas raise concerns. The low percentage of properly escaped output (13%) suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals two flows with unsanitized paths, which, while not categorized as critical or high severity in this analysis, still represent potential attack vectors. The complete lack of nonce checks is another critical omission, particularly for AJAX handlers (even though there are none currently), as it leaves the door open for Cross-Site Request Forgery (CSRF) attacks if such handlers were to be added in the future or if the shortcode were to interact with client-side scripts. The presence of a shortcode is also an entry point, and without specific details on its implementation, it's hard to definitively assess its security, but the lack of overall proper escaping and nonce checks casts doubt.

Given the absence of historical vulnerabilities, the plugin might be considered low risk by some. However, the static analysis reveals fundamental security weaknesses, particularly in output escaping and nonce usage, that could be exploited. The plugin authors should prioritize addressing the output escaping and implement nonce checks for any future additions of AJAX handlers or potentially for the existing shortcode's functionality. Until these are addressed, a moderate risk remains.

Key Concerns

  • Low output escaping percentage (13%)
  • Taint analysis: 2 flows with unsanitized paths
  • No nonce checks implemented
Vulnerabilities
None known

Promociones Mercado Pago Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Promociones Mercado Pago Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
14
2 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

13% escaped16 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settingsPage (TokioMP_OptionsManager.php:264)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Promociones Mercado Pago Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[promociones-mercado-pago] TokioMP_Plugin.php:109
WordPress Hooks 5
actionadmin_noticespromociones-mercado-pago.php:52
actionplugins_loadedipromociones-mercado-pago.php:77
actionadmin_initTokioMP_OptionsManager.php:248
actionadmin_menuTokioMP_Plugin.php:86
actionwp_footerTokioMP_ShortCodeScriptLoader.php:40
Maintenance & Trust

Promociones Mercado Pago Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 12, 2018
PHP min version5.6
Downloads3K

Community Trust

Rating60/100
Number of ratings1
Active installs10
Developer Profile

Promociones Mercado Pago Developer Profile

mauriciowyler

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Promociones Mercado Pago

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/promociones-mercado-pago/css/styles.css

HTML / DOM Fingerprints

Shortcode Output
<!-- Mercado Pago Promos by Tokio Agency -->
FAQ

Frequently Asked Questions about Promociones Mercado Pago