Adicionar Banco Inter ao WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-banco-inter

Adiciona o Banco Inter como método de pagamento ao seu WooCommerce.

30 active installs v2.1.4 PHP 7.0+ WP 4.4+ Updated Oct 18, 2025
banco-interboletoe-commercepixwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Adicionar Banco Inter ao WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Adicionar Banco Inter ao WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "wc-banco-inter" plugin v2.1.4 exhibits several concerning security weaknesses, primarily stemming from a lack of robust input validation and authorization checks across its entry points. The static analysis reveals a single unprotected REST API route, which represents a direct attack vector. Furthermore, the presence of the `unserialize` function is a significant red flag, as it can lead to remote code execution if exploited with malicious serialized data. The absence of any nonce or capability checks across the identified entry points exacerbates these risks, making it easier for unauthenticated or low-privileged users to trigger potentially dangerous code paths.

Despite the absence of known historical vulnerabilities (CVEs), the current code analysis presents a worrying picture. The taint analysis, while limited in scope, shows unsanitized paths, indicating a potential for attackers to inject malicious data. The high percentage of raw SQL queries without prepared statements is another critical concern, opening the door to SQL injection vulnerabilities. While the plugin has a moderate number of file operations and external HTTP requests, the primary risks lie in the insecure handling of inputs and the lack of fundamental security controls.

In conclusion, the "wc-banco-inter" plugin v2.1.4 has a poor security posture. The unprotected REST API, combined with the use of `unserialize` and a complete lack of authorization checks on entry points, creates a high risk of exploitation. The high rate of unescaped output and raw SQL queries further solidify these concerns. While the clean vulnerability history is positive, it does not negate the inherent risks present in the current code.

Key Concerns

  • Unprotected REST API route
  • Unsanitized paths in taint analysis
  • Use of unserialize function
  • 0% SQL queries using prepared statements
  • 0 Nonce checks
  • 0 Capability checks
  • Low percentage of properly escaped output
Vulnerabilities
None known

Adicionar Banco Inter ao WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Adicionar Banco Inter ao WooCommerce Code Analysis

Dangerous Functions
2
Raw SQL Queries
4
0 prepared
Unescaped Output
19
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
42
External Requests
9
Bundled Libraries
0

Dangerous Functions Found

unserializeunserialize( $results[0]->option_value )includes\pix\gatewayPix.php:353
unserializeunserialize($results[0]->option_value),index.php:825

SQL Query Safety

0% prepared4 total queries

Output Escaping

56% escaped43 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wc_banco_inter_sub_registro (admin\register.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Adicionar Banco Inter ao WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/inter/v3/orders/?[A-Za-z0-9]index.php:1059
WordPress Hooks 27
actionadmin_noticesads.php:3
actionadmin_enqueue_scriptsads.php:82
actionwoocommerce_admin_order_data_after_billing_addressincludes\adminDisplay.php:6
filtercron_schedulesincludes\cronBilet.php:14
actionbanco_inter_cron_hookincludes\cronBilet.php:20
actionwoocommerce_order_details_after_order_tableincludes\customerDisplay.php:6
actionwp_enqueue_scriptsincludes\customerDisplay.php:141
actionwp_footerincludes\customerDisplay.php:147
filterwoocommerce_payment_gatewaysincludes\gatewayBillet.php:6
actionwoocommerce_checkout_processincludes\gatewayBillet.php:15
actionwoocommerce_checkout_update_order_metaincludes\gatewayBillet.php:48
actionadmin_menuincludes\menu.php:6
actionplugins_loadedincludes\pix\gatewayPix.php:7
actionadmin_noticesincludes\pix\gatewayPix.php:17
actionwoocommerce_email_before_order_tableincludes\pix\gatewayPix.php:73
actionwoocommerce_api_wc_banco_inter_pixincludes\pix\gatewayPix.php:76
filterwoocommerce_payment_gatewaysincludes\pix\gatewayPix.php:367
actionwoocommerce_checkout_update_order_metaincludes\pix\gatewayPix.php:376
actionhttp_api_curlincludes\registerKeys.php:3
actionwoocommerce_order_details_after_order_tableincludes\statusBillet.php:6
actionplugins_loadedindex.php:33
actionadmin_noticesindex.php:39
actionwoocommerce_email_before_order_tableindex.php:103
actionplugins_loadedindex.php:1036
actionwp_enqueue_scriptsindex.php:1046
actionrest_api_initindex.php:1067
actionactivated_pluginindex.php:1118

Scheduled Events 1

banco_inter_cron_hook
Maintenance & Trust

Adicionar Banco Inter ao WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 18, 2025
PHP min version7.0
Downloads12K

Community Trust

Rating78/100
Number of ratings7
Active installs30
Developer Profile

Adicionar Banco Inter ao WooCommerce Developer Profile

Diletec

2 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Adicionar Banco Inter ao WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-banco-inter/assets/css/bancointer.css/wp-content/plugins/wc-banco-inter/assets/js/bancointer.js
Script Paths
/wp-content/plugins/wc-banco-inter/assets/js/bancointer.js
Version Parameters
wc-banco-inter/assets/css/bancointer.css?ver=wc-banco-inter/assets/js/bancointer.js?ver=

HTML / DOM Fingerprints

CSS Classes
interboleto_descriptioninterboleto_instructions
HTML Comments
<!-- INICIO WC BANCO INTER
Data Attributes
data-plugin-interboletodata-key-interboletodata-crt-interboletodata-cnpj-interboleto
JS Globals
WC_Banco_Inter
FAQ

Frequently Asked Questions about Adicionar Banco Inter ao WooCommerce