Itau Shopline for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-itau-shopline

Itau Shopline gateway for WooCommerce

200 active installs v1.1.1 PHP + WP 4.0+ Updated Aug 10, 2020
itaupaymentshoplinewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Itau Shopline for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Itau Shopline for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wc-itau-shopline" v1.1.1 plugin exhibits a generally positive security posture with no known historical vulnerabilities or critical/high severity issues identified in the static analysis. The plugin demonstrates good practices by having a limited attack surface with no unprotected entry points and a high percentage of properly escaped outputs. The presence of a capability check is also a positive indicator. However, a significant concern arises from the static analysis revealing that 100% of SQL queries are not using prepared statements. This, coupled with taint analysis showing flows with unsanitized paths, suggests a potential for SQL injection vulnerabilities, even if not explicitly flagged as critical in this specific analysis. The lack of nonce checks and the presence of external HTTP requests without further context also warrant attention.

While the plugin's lack of historical vulnerabilities is a strong positive, it's crucial to acknowledge the potential for latent issues indicated by the static code analysis. The critical finding of raw SQL queries and unsanitized taint flows overshadows the otherwise clean security profile. The plugin appears to be built with some security awareness, but the implementation of data handling, particularly around database interactions, needs immediate attention to mitigate risks.

Key Concerns

  • SQL queries not using prepared statements
  • Taint flows with unsanitized paths
  • No nonce checks
Vulnerabilities
None known

Itau Shopline for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Itau Shopline for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
2
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

90% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
payment_redirect (includes\wc-class-itau-shopline-gateway.php:274)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Itau Shopline for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwoocommerce_api_wc_itau_shopline_gatewayincludes\wc-class-itau-shopline-gateway.php:64
actionwoocommerce_email_after_order_tableincludes\wc-class-itau-shopline-gateway.php:67
filtercron_schedulesincludes\wc-class-itau-shopline-sounder.php:18
actionwc_itau_shopline_sounderincludes\wc-class-itau-shopline-sounder.php:19
actioninitwc-itau-shopline.php:67
filterwoocommerce_payment_gatewayswc-itau-shopline.php:74
actionadmin_noticeswc-itau-shopline.php:77
actionplugins_loadedwc-itau-shopline.php:172

Scheduled Events 1

wc_itau_shopline_sounder
Maintenance & Trust

Itau Shopline for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 10, 2020
PHP min version
Downloads11K

Community Trust

Rating96/100
Number of ratings12
Active installs200
Developer Profile

Itau Shopline for WooCommerce Developer Profile

Claudio Sanches

17 plugins · 134K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
831 days
View full developer profile
Detection Fingerprints

How We Detect Itau Shopline for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-itau-shopline/assets/css/style.css/wp-content/plugins/wc-itau-shopline/assets/js/script.js
Script Paths
/wp-content/plugins/wc-itau-shopline/assets/js/script.js
Version Parameters
wc-itau-shopline/assets/css/style.css?ver=wc-itau-shopline/assets/js/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Itau Shopline for WooCommerce is free software: you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation, either version 2 of the License, or * any later version. * * Itau Shopline for WooCommerce is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with Itau Shopline for WooCommerce. If not, see * <https://www.gnu.org/licenses/gpl-2.0.txt>. --><!-- Itau Shopline for WooCommerce main class. --><!-- Itau Shopline for WooCommerce API class. --><!-- Itau Shopline for WooCommerce Sounder class. -->+4 more
JS Globals
window.WC_Itau_Shopline_Gateway
REST Endpoints
/wp-json/wc-itau-shopline-gateway
FAQ

Frequently Asked Questions about Itau Shopline for WooCommerce