
Promociones Mercado Pago Security & Risk Analysis
wordpress.org/plugins/promociones-mercado-pagoLists Mercado Pago credit and debit card active promotions.
Is Promociones Mercado Pago Safe to Use in 2026?
Generally Safe
Score 85/100Promociones Mercado Pago has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'promociones-mercado-pago' v0.1 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) associated with this plugin, and its code signals indicate the absence of dangerous functions and SQL queries that are not properly prepared. Furthermore, the plugin uses capability checks for some operations and performs file operations and external HTTP requests in a controlled manner.
However, several areas raise concerns. The low percentage of properly escaped output (13%) suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals two flows with unsanitized paths, which, while not categorized as critical or high severity in this analysis, still represent potential attack vectors. The complete lack of nonce checks is another critical omission, particularly for AJAX handlers (even though there are none currently), as it leaves the door open for Cross-Site Request Forgery (CSRF) attacks if such handlers were to be added in the future or if the shortcode were to interact with client-side scripts. The presence of a shortcode is also an entry point, and without specific details on its implementation, it's hard to definitively assess its security, but the lack of overall proper escaping and nonce checks casts doubt.
Given the absence of historical vulnerabilities, the plugin might be considered low risk by some. However, the static analysis reveals fundamental security weaknesses, particularly in output escaping and nonce usage, that could be exploited. The plugin authors should prioritize addressing the output escaping and implement nonce checks for any future additions of AJAX handlers or potentially for the existing shortcode's functionality. Until these are addressed, a moderate risk remains.
Key Concerns
- Low output escaping percentage (13%)
- Taint analysis: 2 flows with unsanitized paths
- No nonce checks implemented
Promociones Mercado Pago Security Vulnerabilities
Promociones Mercado Pago Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Promociones Mercado Pago Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Promociones Mercado Pago Maintenance & Trust
Maintenance Signals
Community Trust
Promociones Mercado Pago Alternatives
MercadoPago Plus para WooCommerce
woo-mercadopago-gateway-checkout
Conectá MercadoPago Plus para tu tienda de WooCommerce
Mercado Pago payments for WooCommerce
woocommerce-mercadopago
Offer to your clients the best experience in e-Commerce by using Mercado Pago as your payment method.
Pagopar – WooCommerce Gateway
pagopar-woocommerce-gateway
Vendé a todo el país con los principales medios de pago.
WPeComm Mercado Pago Module Oficial
wpecomm-mercado-pago-module
This is the oficial module of Mercado Pago for WP-eCommerce plugin.
Link Nacional Payment Gateway for MercadoPago and GiveWP
lknmp-gateway-givewp
Link Nacional MercadoPago payment option for GiveWP.
Promociones Mercado Pago Developer Profile
1 plugin · 10 total installs
How We Detect Promociones Mercado Pago
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/promociones-mercado-pago/css/styles.cssHTML / DOM Fingerprints
<!-- Mercado Pago Promos by Tokio Agency -->