
Vindi Security & Risk Analysis
wordpress.org/plugins/vindi-pagamentosA Vindi é um Hub de Pagamentos Inteligente que simplifica a cobrança de seus clientes oferendo soluções completas para pagamentos online, incluindo ch …
Is Vindi Safe to Use in 2026?
Generally Safe
Score 100/100Vindi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'vindi-pagamentos' plugin version 1.1.5 demonstrates a generally strong security posture, with no recorded vulnerabilities or critical taint flows. The code analysis indicates good practices in several areas, including the prevalent use of prepared statements for SQL queries (88%) and a high percentage of properly escaped outputs (76%). The presence of nonce checks for all AJAX handlers and capability checks for a significant portion of entry points are also positive signs. However, there are notable concerns regarding the attack surface. With 22 AJAX handlers, 5 are identified as lacking authentication checks. This represents a significant entry point that could be exploited if these handlers perform sensitive operations or process user-supplied data without proper authorization. While no critical or high severity issues were found in the static analysis or taint flows, the unprotected AJAX handlers present a clear risk that warrants attention.
Key Concerns
- Unprotected AJAX handlers
Vindi Security Vulnerabilities
Vindi Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Vindi Attack Surface
AJAX Handlers 22
WordPress Hooks 86
Scheduled Events 1
Maintenance & Trust
Vindi Maintenance & Trust
Maintenance Signals
Community Trust
Vindi Alternatives
Payment Gateways by User Roles for WooCommerce
payment-gateways-by-user-roles-for-woocommerce
Set user roles to include/exclude for WooCommerce payment gateways to show up.
Country Based Payments for WooCommerce
woocommerce-country-based-payments
Choose which payment gateway will be available in country/countries.
Fake Pay For WooCommerce
fake-pay-for-woocommerce
A simple pass-through WooCommerce payment gateway that can be used for testing orders with an admin account.
Disable Payment Methods based on cart conditions for WooCommerce
woo-conditional-payment-gateways
Enable or disable WooCommerce payment gateways based on cart conditions like the order total.
Viva Payments – Viva Wallet WooCommerce Payment Gateway
woo-payment-gateway-for-vivapayments
Woocommerce Viva Payments - Viva Wallet payment gateway plug-in.
Vindi Developer Profile
1 plugin · 80 total installs
How We Detect Vindi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vindi-pagamentos/styles/index.css/wp-content/plugins/vindi-pagamentos/build/index.js/wp-content/plugins/vindi-pagamentos/build/admin.js/wp-content/plugins/vindi-pagamentos/build/vindi-pagamentos-gateway-checkout.js/wp-content/plugins/vindi-pagamentos/build/index.js/wp-content/plugins/vindi-pagamentos/build/admin.js/wp-content/plugins/vindi-pagamentos/build/vindi-pagamentos-gateway-checkout.jsvindi-pagamentos/styles/index.css?ver=vindi-pagamentos/build/index.js?ver=vindi-pagamentos/build/admin.js?ver=vindi-pagamentos/build/vindi-pagamentos-gateway-checkout.js?ver=HTML / DOM Fingerprints
vindi-pagamentos-wrappervindi-pagamentos-modalvindi-pagamentos-admin-wrapper<!-- Vindi Pagamentos --><!-- Vindi Pagamentos - Vindi Core --><!-- Vindi Pagamentos - Admin --><!-- Vindi Pagamentos - Gateway Checkout -->data-vindi-gateway-checkout-configdata-vindi-checkout-urlvindi_pagamentos_checkout_paramsvindi_pagamentos_admin_paramsVindiPagamentos/wp-json/vindi-pagamentos/v1/create-order/wp-json/vindi-pagamentos/v1/webhook/wp-json/vindi-pagamentos/v1/pix/generate-code/wp-json/vindi-pagamentos/v1/boleto/generate-bank-slip