
ilGhera Carta Docente for WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-carta-docenteAbilita in WooCommerce il pagamento con Carta del Docente.
Is ilGhera Carta Docente for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ilGhera Carta Docente for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wc-carta-docente" v1.5.1 demonstrates a generally good security posture with several positive indicators. It has no known historical vulnerabilities (CVEs), which is a significant strength. The code analysis shows a complete absence of dangerous functions and all SQL queries are properly prepared, mitigating common injection risks. Furthermore, all identified entry points (AJAX handlers, shortcodes) are protected by nonce checks, and there are no external HTTP requests, reducing the attack surface for remote code execution or SSRF vulnerabilities.
However, there are areas for concern. A notable issue is the relatively low percentage of properly escaped outputs (63%), which leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal critical or high severity unsanitized paths, the presence of two flows with unsanitized paths, even if categorized lower, warrants attention as it indicates potential for data manipulation or unauthorized access if inputs are not handled with extreme care. The absence of capability checks on AJAX handlers, while protected by nonces, could still allow unintended actions by authenticated users who might not possess the correct privileges for those operations.
In conclusion, the plugin is strong in preventing SQL injection and has a clean vulnerability history. The primary weaknesses lie in the insufficient output escaping and the potential for XSS. The presence of unsanitized paths, while not critically rated, is a risk that should be addressed. Improving output escaping and carefully reviewing the identified unsanitized paths would significantly enhance the plugin's security.
Key Concerns
- Unescaped output detected
- Flows with unsanitized paths
- No capability checks on AJAX
ilGhera Carta Docente for WooCommerce Security Vulnerabilities
ilGhera Carta Docente for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
ilGhera Carta Docente for WooCommerce Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
ilGhera Carta Docente for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ilGhera Carta Docente for WooCommerce Alternatives
WC Carte Cultura
wc-carte-cultura
Abilita in WooCommerce il pagamento con Carte Cultura.
Paystack WooCommerce Payment Gateway
woo-paystack
Paystack for WooCommerce allows your WooCommerce store to accept secure payments from multiple local and global payment channels.
Montonio for WooCommerce
montonio-for-woocommerce
Montonio is a complete checkout solution for online stores that includes all popular payment methods (local banks, card payments, Apple Pay, Google Pa …
NETOPIA Payments Payment Gateway
netopia-payments-payment-gateway
NETOPIA Payments Payment Gateway extends WooCommerce payment options by adding NETOPIA's Payment Gateway options.
SumUp Payment Gateway For WooCommerce
sumup-payment-gateway-for-woocommerce
The SumUp plugin for WooCommerce allows businesses to securely process payments online. Accept payments from customers using a range of payment method …
ilGhera Carta Docente for WooCommerce Developer Profile
13 plugins · 2K total installs
How We Detect ilGhera Carta Docente for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-carta-docente/css/wc-carta-docente.css/wp-content/plugins/wc-carta-docente/css/wc-carta-docente-admin.css/wp-content/plugins/wc-carta-docente/js/wc-carta-docente-admin.js/wp-content/plugins/wc-carta-docente/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.css/wp-content/plugins/wc-carta-docente/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js/wp-content/plugins/wc-carta-docente/js/tzCheckbox/js/script.js/wp-content/plugins/wc-carta-docente/js/wc-carta-docente-admin.js/wp-content/plugins/wc-carta-docente/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js/wp-content/plugins/wc-carta-docente/js/tzCheckbox/js/script.jswc-carta-docente/css/wc-carta-docente.css?ver=wc-carta-docente/css/wc-carta-docente-admin.css?ver=wc-carta-docente/js/wc-carta-docente-admin.js?ver=wc-carta-docente/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.css?ver=wc-carta-docente/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js?ver=wc-carta-docente/js/tzCheckbox/js/script.js?ver=HTML / DOM Fingerprints
wccd-stylewccd-admin-styledata-wccd-del-cert-noncedata-wccd-add-cat-noncewccdData[checkout-url]