Tools for MercadoPago and WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-kmercadopago-gpl

Plataforma de pago MercadoPago para Argentina, Mexico, Brazil, Colombia, Chile, Peru and Uruguay. Solo Checkout Basico (Pro).

40 active installs v1.0.8 PHP 5.6+ WP 4.9.10+ Updated Dec 3, 2023
ecommercemercadopagowoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tools for MercadoPago and WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Tools for MercadoPago and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "wc-kmercadopago-gpl" plugin v1.0.8 exhibits a generally strong security posture based on the static analysis. The plugin demonstrates good security practices by implementing nonce checks and capability checks for its AJAX handlers. The code also shows a high degree of diligence in output escaping, with 99% of outputs being properly escaped, significantly mitigating the risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the vast majority of SQL queries (80%) utilize prepared statements, which is a crucial defense against SQL injection attacks. The absence of known CVEs and any recorded historical vulnerabilities suggests a mature and well-maintained codebase, or at least one that hasn't attracted significant attention for security flaws.

Despite the positive indicators, a few areas warrant attention. While the attack surface is small with only two entry points (AJAX handlers), the static analysis indicates that none are currently unprotected. However, a thorough review of the specific AJAX handler implementations is recommended to ensure that the existing capability checks are robust and correctly applied. The presence of file operations and external HTTP requests, while not inherently insecure, represents potential avenues for exploitation if not handled with extreme care and proper validation. The analysis did not reveal any critical or high-severity taint flows, which is a very positive sign. Overall, the plugin appears to be built with security in mind, but continuous vigilance and thorough code review of its interaction points are always recommended for any plugin.

Vulnerabilities
None known

Tools for MercadoPago and WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tools for MercadoPago and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
1
86 escaped
Nonce Checks
2
Capability Checks
2
File Operations
5
External Requests
8
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

99% escaped87 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-wc-kmercadopagogpl-manager> (includes\class-wc-kmercadopagogpl-manager.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Tools for MercadoPago and WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_kmercadopagogpl_set_device_idincludes\functions.php:191
noprivwp_ajax_kmercadopagogpl_set_device_idincludes\functions.php:192
WordPress Hooks 34
filterwoocommerce_integrationsclass-wc-kmercadopagogpl.php:61
filterwoocommerce_payment_gatewaysclass-wc-kmercadopagogpl.php:62
actionadmin_noticesclass-wc-kmercadopagogpl.php:64
actionplugins_loadedclass-wc-kmercadopagogpl.php:162
actionwoocommerce_customer_changed_subscription_to_cancelledincludes\class-wc-kmercadopagogpl-basic.php:74
actionwoocommerce_order_status_refundedincludes\class-wc-kmercadopagogpl-basic.php:75
actionwoocommerce_order_status_cancelledincludes\class-wc-kmercadopagogpl-basic.php:76
actionwp_loadedincludes\class-wc-kmercadopagogpl-manager.php:151
actionwp_headincludes\class-wc-kmercadopagogpl-manager.php:152
actionwoocommerce_kmercadopagogpl_check_ipn_responseincludes\class-wc-kmercadopagogpl-manager.php:153
actionvalid_mercadopago_ipn_requestincludes\class-wc-kmercadopagogpl-manager.php:154
actionwoocommerce_kmercadopagogpl_metaboxincludes\class-wc-kmercadopagogpl-manager.php:155
actionwoocommerce_order_status_changedincludes\class-wc-kmercadopagogpl-manager.php:158
actionwoocommerce_review_order_after_submitincludes\class-wc-kmercadopagogpl-manager.php:159
actionwp_headincludes\class-wc-kmercadopagogpl-manager.php:160
actionwp_enqueue_scriptsincludes\class-wc-kmercadopagogpl-manager.php:161
actionadmin_noticesincludes\class-wc-kmercadopagogpl-manager.php:182
actionadmin_noticesincludes\class-wc-kmercadopagogpl-manager.php:185
actionadmin_noticesincludes\class-wc-kmercadopagogpl-manager.php:193
actionadmin_noticesincludes\class-wc-kmercadopagogpl-manager.php:196
actionadmin_noticesincludes\class-wc-kmercadopagogpl-manager.php:199
filterscript_loader_tagincludes\class-wc-kmercadopagogpl-manager.php:279
actionadmin_noticesincludes\functions.php:13
actionwoocommerce_after_add_to_cart_buttonincludes\functions.php:38
filterwoocommerce_checkout_fieldsincludes\functions.php:47
actionadd_meta_boxesincludes\functions.php:90
actiontemplate_redirectincludes\functions.php:106
actiondo_kmercadopagogpl_hourly_checkincludes\functions.php:155
actionwoocommerce_cart_calculate_feesincludes\functions.php:158
actionwp_enqueue_scriptsincludes\functions.php:194
actionproduct_cat_add_form_fieldsincludes\functions.php:219
actionproduct_cat_edit_form_fieldsincludes\functions.php:243
filterwoocommerce_product_data_tabsincludes\functions.php:277
actionwoocommerce_product_data_panelsincludes\functions.php:289

Scheduled Events 1

do_kmercadopagogpl_hourly_check
Maintenance & Trust

Tools for MercadoPago and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedDec 3, 2023
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Tools for MercadoPago and WooCommerce Developer Profile

kijam

2 plugins · 90 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tools for MercadoPago and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-kmercadopago-gpl/assets/js/kmercadopagogpl-admin.js/wp-content/plugins/wc-kmercadopago-gpl/assets/css/kmercadopagogpl-admin.css/wp-content/plugins/wc-kmercadopago-gpl/assets/js/kmercadopagogpl-public.js/wp-content/plugins/wc-kmercadopago-gpl/assets/css/kmercadopagogpl-public.css
Script Paths
/wp-content/plugins/wc-kmercadopago-gpl/assets/js/kmercadopagogpl-admin.js/wp-content/plugins/wc-kmercadopago-gpl/assets/js/kmercadopagogpl-public.js
Version Parameters
wc-kmercadopago-gpl/assets/js/kmercadopagogpl-admin.js?ver=wc-kmercadopago-gpl/assets/css/kmercadopagogpl-admin.css?ver=wc-kmercadopago-gpl/assets/js/kmercadopagogpl-public.js?ver=wc-kmercadopago-gpl/assets/css/kmercadopagogpl-public.css?ver=

HTML / DOM Fingerprints

CSS Classes
kmercadopagogpl-admin-sectionkmercadopagogpl-settingskmercadopagogpl-gateway-settingskmercadopagogpl-payment-form
Data Attributes
data-plugin-name="wc-kmercadopago-gpl"
JS Globals
kmercadopagogpl_ajax_object
FAQ

Frequently Asked Questions about Tools for MercadoPago and WooCommerce