
CoffeeCode – Checkout for Getnet and WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-checkout-getnetCoffeeCode - Checkout for Getnet and WooCommerce
Is CoffeeCode – Checkout for Getnet and WooCommerce Safe to Use in 2026?
Generally Safe
Score 98/100CoffeeCode – Checkout for Getnet and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The wc-checkout-getnet plugin version 1.12.0 presents a mixed security posture. On the positive side, the code demonstrates strong practices regarding SQL queries, consistently utilizing prepared statements. Furthermore, the vast majority of output is properly escaped, and taint analysis shows no critical or high severity vulnerabilities, indicating good input sanitization for the analyzed flows. However, a significant concern arises from the large attack surface presented by AJAX handlers. A considerable number of these handlers (13 out of 17) lack authentication checks, leaving them open to potential unauthorized access or manipulation.
The vulnerability history reveals three medium-severity CVEs, all of which are now patched. The commonality of Cross-site Scripting vulnerabilities in the past suggests a historical weakness in output neutralization, though the current static analysis indicates significant improvement in this area. Despite the absence of currently unpatched CVEs and critical taint issues, the unprotected AJAX endpoints represent a tangible and immediate risk that could be exploited if not properly secured. The plugin also bundles Guzzle, which could be a point of concern if it's an outdated version, though this is not explicitly detailed in the provided data.
Key Concerns
- 13 unprotected AJAX handlers
- 3 medium severity CVEs historically
- Bundled library (Guzzle) may be outdated
CoffeeCode – Checkout for Getnet and WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Reflected Cross-Site Scripting
Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Plugin Oficial – Getnet para WooCommerce <= 1.8.0 - Reflected Cross-Site Scripting
CoffeeCode – Checkout for Getnet and WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
CoffeeCode – Checkout for Getnet and WooCommerce Attack Surface
AJAX Handlers 17
WordPress Hooks 42
Maintenance & Trust
CoffeeCode – Checkout for Getnet and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
CoffeeCode – Checkout for Getnet and WooCommerce Alternatives
Amazon Pay for WooCommerce
woocommerce-gateway-amazon-payments-advanced
Install the Amazon Pay plugin for your WooCommerce store and take advantage of a seamless checkout experience
myPOS Checkout
mypos-virtual-for-woocommerce
One-click checkout with instant settlement. Accept all major cards, Apple Pay and Google Pay. No setup costs or monthly fees.
ePayco plugin for WooCommerce
epayco-gateway
The official ePayco plugin for WooCommerce allows seamless payment processing for your online store.
NOWPayments for WooCommerce – Crypto Payment Gateway
nowpayments-for-woocommerce
Accept Bitcoin, Ethereum, and 300+ cryptocurrencies in WooCommerce using the official NOWPayments crypto payment gateway.
imoje
imoje
Add payment via imoje to WooCommerce
CoffeeCode – Checkout for Getnet and WooCommerce Developer Profile
1 plugin · 300 total installs
How We Detect CoffeeCode – Checkout for Getnet and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-checkout-getnet/dist/frontend.js/wp-content/plugins/wc-checkout-getnet/dist/frontend.css/wp-content/plugins/wc-checkout-getnet/dist/admin.js/wp-content/plugins/wc-checkout-getnet/dist/admin.css/wp-content/plugins/wc-checkout-getnet/dist/frontend.js/wp-content/plugins/wc-checkout-getnet/dist/admin.jswc-checkout-getnet/dist/frontend.js?ver=wc-checkout-getnet/dist/frontend.css?ver=wc-checkout-getnet/dist/admin.js?ver=wc-checkout-getnet/dist/admin.css?ver=HTML / DOM Fingerprints
getnet-update-warningdata-getnet-dismiss-update-warningwpParams