
Transbank Webpay Security & Risk Analysis
wordpress.org/plugins/transbank-webpay-plus-restRecibe pagos en línea con tarjetas de crédito, débito y prepago en tu WooCommerce a través de Webpay Plus y Webpay Oneclick.
Is Transbank Webpay Safe to Use in 2026?
Generally Safe
Score 99/100Transbank Webpay has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The Transbank Webpay Plus REST plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by extensively using prepared statements for its SQL queries and performing capability checks on a reasonable number of actions. The absence of critical or high severity taint flows is also a positive indicator, suggesting that untrusted data is generally handled with care in the analyzed code paths.
However, significant concerns arise from the plugin's attack surface. All five identified AJAX handlers lack authentication checks, presenting a direct pathway for unauthenticated users to interact with potentially sensitive functionalities. Furthermore, the output escaping is only properly implemented in 50% of cases, increasing the risk of cross-site scripting (XSS) vulnerabilities. The plugin's vulnerability history, specifically a high-severity SQL injection vulnerability discovered in April 2023, though currently patched, indicates a past weakness in input sanitization for SQL commands, reinforcing the need for vigilance in handling user-supplied data.
Overall, while the plugin shows strengths in database query security and privilege checks, the lack of authentication on AJAX endpoints and the inconsistent output escaping are critical weaknesses that elevate the risk profile. The past SQL injection vulnerability also suggests a pattern that warrants careful monitoring and potentially more rigorous security auditing.
Key Concerns
- 5 AJAX handlers without auth checks
- 50% of outputs not properly escaped
- 1 High severity vulnerability in history
- Bundled library Guzzle
Transbank Webpay Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Transbank Webpay REST <= 1.6.6 - Authenticated (Administrator+) SQL Injection via orderby
Transbank Webpay Release Timeline
Transbank Webpay Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Transbank Webpay Attack Surface
AJAX Handlers 5
WordPress Hooks 21
Maintenance & Trust
Transbank Webpay Maintenance & Trust
Maintenance Signals
Community Trust
Transbank Webpay Alternatives
VentiPay
ventipay
Plugin oficial de Venti para WooCommerce
SimplePay WooCommerce
simplepay
Este plugin te permite integrar SimplePay para que tu tienda de WooCommerce pueda aceptar todo tipo de pagos chilenos. Wbpay Plus, Webpay One Click, …
Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce
wc-transbank-webpay-plus-rest
Vende con las tarjetas de Webpay Plus en tu carro de compras con WooCommerce. Medio de Pago de Transbank.
Zafepay
zafepay
Con Zafepay tus clientes pagan con tarjeta de crédito, débito, prepago y transferencia. Puedes cobrar en cuotas sin interés!
Transbank Webpay Developer Profile
1 plugin · 10K total installs
How We Detect Transbank Webpay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/transbank-webpay-plus-rest/css/tbk.css/wp-content/plugins/transbank-webpay-plus-rest/css/font-awesome/all.css/wp-content/plugins/transbank-webpay-plus-rest/js/admin.js/wp-content/plugins/transbank-webpay-plus-rest/js/swal.min.js/wp-content/plugins/transbank-webpay-plus-rest/js/admin.js/wp-content/plugins/transbank-webpay-plus-rest/js/swal.min.jstbk-styles?ver=1.1HTML / DOM Fingerprints
tbk_tabajax_object/wp-json/transbank/v1/transaction/status/wp-json/transbank/v1/healthcheck