
SEPA Girocode Security & Risk Analysis
wordpress.org/plugins/sepa-girocodeCreate EPC-Codes (in Germany known as Girocode) for money transfer | Girocode-Barcode für SEPA-Überweisungen erstellen
Is SEPA Girocode Safe to Use in 2026?
Mostly Safe
Score 78/100SEPA Girocode is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "sepa-girocode" v0.5.1 plugin exhibits several concerning security practices despite a limited attack surface. While the plugin has no exposed AJAX handlers or REST API routes without authentication, and no critical or high severity taint flows were identified, the codebase has significant weaknesses. The lack of any nonce or capability checks is a major concern, as it implies that even entry points that exist could be exploited without proper authorization. Furthermore, the plugin performs raw SQL queries without using prepared statements, which opens the door to SQL injection vulnerabilities. The presence of a medium severity Cross-Site Scripting (XSS) vulnerability in its history, despite the latest vulnerability being dated in the future (which is likely a data error and should be treated as a current concern), highlights a recurring issue with input sanitization and output escaping, further evidenced by only 58% of output being properly escaped. The use of the bundled TCPDF library also raises a flag, as bundled libraries can become outdated and introduce their own vulnerabilities if not actively maintained.
Key Concerns
- Unpatched medium severity CVE
- Raw SQL queries without prepared statements
- No nonce checks on entry points
- No capability checks on entry points
- Significant portion of output not escaped
- Flows with unsanitized paths
- Bundled TCPDF library
SEPA Girocode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SEPA Girocode <= 0.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
SEPA Girocode Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
SEPA Girocode Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
SEPA Girocode Maintenance & Trust
Maintenance Signals
Community Trust
SEPA Girocode Alternatives
GiroCode
girocode
This plugin displays GiroCodes for easy bank transfers. A GiroCode is a QR code with data for a transfer which can be scanned into a banking app.
Donation QR Block
donation-qr-block
Display an EPC/GiroCode QR code for SEPA bank donations. Scannable by banking apps to pre-fill transfer details.
Viva.com | Smart Checkout for WooCommerce
viva-com-smart-for-woocommerce
Take secure online payments on your WooCommerce store with Viva.com Smart Checkout. ---
CSSIgniter Shortcodes
cssigniter-shortcodes
This plugin defines and allows you to use a lot of useful shortcodes. Need a button? Sure. A message box? You know we have it.
Icon Separator
icon-separator
A simple, lightweight, accessibility-ready icon separator block.
SEPA Girocode Developer Profile
1 plugin · 20 total installs
How We Detect SEPA Girocode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sepa-girocode/images/girocode.pngHTML / DOM Fingerprints
data-sepa-girocode-classsepa_girocode_class<img src="index.php?sepa-girocode=show-code&key=<a href="index.php?sepa-girocode=get-codefile&key=