
SimplePay WooCommerce Security & Risk Analysis
wordpress.org/plugins/simplepayEste plugin te permite integrar SimplePay para que tu tienda de WooCommerce pueda aceptar todo tipo de pagos chilenos. Wbpay Plus, Webpay One Click, …
Is SimplePay WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100SimplePay WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simplepay" plugin v0.1.4 exhibits a mixed security posture. On the positive side, it has no known CVEs, a lack of file operations, external HTTP requests, and SQL queries are all prepared. The attack surface, as reported by static analysis, is zero, which is an excellent sign for security. However, there are significant concerns regarding output escaping. With 14 outputs and 0% properly escaped, this indicates a high risk of cross-site scripting (XSS) vulnerabilities. Taint analysis also reveals two flows with unsanitized paths, further reinforcing the XSS risk. The absence of nonce and capability checks, combined with the lack of auth checks on AJAX handlers (though none are reported), suggests that even if entry points were present, they might not be adequately protected against unauthorized actions.
The plugin's vulnerability history is clean, which is a positive indicator of past development practices. However, this does not mitigate the current risks identified in the static analysis. The zero attack surface is a significant strength, but it is overshadowed by the critical issue of unescaped output and unsanitized paths. The bundled Guzzle library, while not explicitly flagged as outdated, should be monitored as bundled libraries can become a vector for vulnerabilities if not kept up-to-date. In conclusion, while the plugin has a clean vulnerability history and no apparent SQL injection or direct file manipulation risks, the severe lack of output escaping and unsanitized paths presents a substantial security risk that needs immediate attention.
Key Concerns
- Unescaped output: 14 total outputs, 0% properly escaped
- Taint analysis: 2 flows with unsanitized paths
- Missing nonce checks: 0
- Missing capability checks: 0
- Bundled library: Guzzle (potential for outdated)
SimplePay WooCommerce Security Vulnerabilities
SimplePay WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
SimplePay WooCommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
SimplePay WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
SimplePay WooCommerce Alternatives
VentiPay
ventipay
Plugin oficial de Venti para WooCommerce
Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce
wc-transbank-webpay-plus-rest
Vende con las tarjetas de Webpay Plus en tu carro de compras con WooCommerce. Medio de Pago de Transbank.
Transbank Webpay
transbank-webpay-plus-rest
Recibe pagos en línea con tarjetas de crédito, débito y prepago en tu WooCommerce a través de Webpay Plus y Webpay Oneclick.
Comunas de Chile para WooCommerce
comunas-de-chile-para-woocommerce
Agrega las Comunas de Chile a WooCommerce para mejorar la experiencia de envío.
Campo RUT para CF7
add-campo-rut-cf7
Agrega un campo de tipo RUT (Chileno) a Contact Form 7. Este plugin depende de Contact Form 7.
SimplePay WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect SimplePay WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simplepay/assets/css/simplepay-woocommerce.css/wp-content/plugins/simplepay/assets/js/simplepay-woocommerce.js/wp-content/plugins/simplepay/assets/js/simplepay-woocommerce.jssimplepay-woocommerce.css?ver=simplepay-woocommerce.js?ver=HTML / DOM Fingerprints
simplepay-thanks<!-- SimplePay Thanks -->simplepay_checkout_params/wp-json/simplepay/v1/transactions