MultiPay – Pagamentos e Fidelidade para WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-multipay

Que tal potencializar as vendas da sua loja virtual com um checkout de pagamento seguro e ágil? Plugin Multi para e-commerce: intuitivo e de fácil int …

10 active installs v0.1.1 PHP 5.6+ WP 4.5+ Updated Apr 5, 2024
fidelidademultifidelidademultipaypagamentoswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MultiPay – Pagamentos e Fidelidade para WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

MultiPay – Pagamentos e Fidelidade para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The wc-multipay plugin v0.1.1 exhibits a strong initial security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, and the high percentage of properly escaped output are positive indicators. The limited attack surface with no identified unprotected entry points is also commendable, suggesting a cautious approach to plugin development.

However, several areas warrant attention. The plugin performs one file operation and one external HTTP request, which, while not inherently risky, represent potential attack vectors if not handled with strict validation and sanitization. Furthermore, the complete lack of nonce checks on any potential entry points is a significant concern. While the static analysis didn't report any taint flows or unpatched vulnerabilities, the absence of nonce checks means that any future or undiscovered vulnerabilities could be exacerbated by Cross-Site Request Forgery (CSRF) attacks.

In conclusion, the plugin demonstrates good practices in areas like output escaping and prepared statements. The lack of historical vulnerabilities is positive but should not breed complacency. The primary weaknesses lie in the potential for insecure file and external HTTP operations, and critically, the complete absence of nonce checks, which significantly increases the risk of CSRF attacks. More comprehensive taint analysis would be beneficial to fully assess the security of file and HTTP operations.

Key Concerns

  • Missing nonce checks on AJAX/entry points
  • Potential insecure file operations
  • Potential insecure external HTTP requests
Vulnerabilities
None known

MultiPay – Pagamentos e Fidelidade para WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MultiPay – Pagamentos e Fidelidade para WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

MultiPay – Pagamentos e Fidelidade para WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
33 escaped
Nonce Checks
0
Capability Checks
4
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

92% escaped36 total outputs
Attack Surface

MultiPay – Pagamentos e Fidelidade para WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitincludes/wcClassMultiPay.php:19
filterwoocommerce_payment_gatewaysincludes/wcClassMultiPay.php:27
filterwoocommerce_available_payment_gatewaysincludes/wcClassMultiPay.php:28
actionadmin_noticesincludes/wcClassMultiPay.php:32
actionadmin_noticesincludes/wcClassMultiPay.php:35
actionwoocommerce_api_wc_multipay_gatewayincludes/wcClassMultiPayGateway.php:56
actionwoocommerce_order_status_cancelledincludes/wcClassMultiPayGateway.php:59
actionwoocommerce_order_status_refundedincludes/wcClassMultiPayGateway.php:60
actionwoocommerce_thankyouincludes/wcClassMultiPayGateway.php:61
actionwoocommerce_update_orderincludes/wcClassMultiPayGateway.php:64
actionplugins_loadedwoo-multipay.php:82
Maintenance & Trust

MultiPay – Pagamentos e Fidelidade para WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 5, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

MultiPay – Pagamentos e Fidelidade para WooCommerce Developer Profile

Multifidelidade

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MultiPay – Pagamentos e Fidelidade para WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-multipay/assets/css/general.css/wp-content/plugins/wc-multipay/assets/js/general.js/wp-content/plugins/wc-multipay/assets/css/style.css
Script Paths
/wp-content/plugins/wc-multipay/assets/js/general.js
Version Parameters
wc-multipay/assets/css/general.css?ver=wc-multipay/assets/js/general.js?ver=wc-multipay/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wc_pay_multipay_section
HTML Comments
<!-- MultiPay payment section --><!-- End MultiPay payment section --><!-- MultiPay gateway options --><!-- End MultiPay gateway options -->
Data Attributes
data-multipay-gatewaydata-multipay-order-iddata-multipay-payment-url
JS Globals
wc_multipay_params
REST Endpoints
/wp-json/wc-multipay-gateway/v1/create_payment
FAQ

Frequently Asked Questions about MultiPay – Pagamentos e Fidelidade para WooCommerce