
MultiPay – Pagamentos e Fidelidade para WooCommerce Security & Risk Analysis
wordpress.org/plugins/wc-multipayQue tal potencializar as vendas da sua loja virtual com um checkout de pagamento seguro e ágil? Plugin Multi para e-commerce: intuitivo e de fácil int …
Is MultiPay – Pagamentos e Fidelidade para WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100MultiPay – Pagamentos e Fidelidade para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wc-multipay plugin v0.1.1 exhibits a strong initial security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, and the high percentage of properly escaped output are positive indicators. The limited attack surface with no identified unprotected entry points is also commendable, suggesting a cautious approach to plugin development.
However, several areas warrant attention. The plugin performs one file operation and one external HTTP request, which, while not inherently risky, represent potential attack vectors if not handled with strict validation and sanitization. Furthermore, the complete lack of nonce checks on any potential entry points is a significant concern. While the static analysis didn't report any taint flows or unpatched vulnerabilities, the absence of nonce checks means that any future or undiscovered vulnerabilities could be exacerbated by Cross-Site Request Forgery (CSRF) attacks.
In conclusion, the plugin demonstrates good practices in areas like output escaping and prepared statements. The lack of historical vulnerabilities is positive but should not breed complacency. The primary weaknesses lie in the potential for insecure file and external HTTP operations, and critically, the complete absence of nonce checks, which significantly increases the risk of CSRF attacks. More comprehensive taint analysis would be beneficial to fully assess the security of file and HTTP operations.
Key Concerns
- Missing nonce checks on AJAX/entry points
- Potential insecure file operations
- Potential insecure external HTTP requests
MultiPay – Pagamentos e Fidelidade para WooCommerce Security Vulnerabilities
MultiPay – Pagamentos e Fidelidade para WooCommerce Release Timeline
MultiPay – Pagamentos e Fidelidade para WooCommerce Code Analysis
Output Escaping
MultiPay – Pagamentos e Fidelidade para WooCommerce Attack Surface
WordPress Hooks 11
Maintenance & Trust
MultiPay – Pagamentos e Fidelidade para WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
MultiPay – Pagamentos e Fidelidade para WooCommerce Alternatives
Vindi
vindi-pagamentos
A Vindi é um Hub de Pagamentos Inteligente que simplifica a cobrança de seus clientes oferendo soluções completas para pagamentos online, incluindo ch …
PagSeguro International Payment Gateway for WooCommerce
pagseguro-internacional-payment-gateway-for-woocommerce
PagSeguro International Payment Gateway for WooCommerce allows merchants to accept over 140 Latin American payment methods directly on your website, t …
Simulador de Parcelas para Loja Virtual
simulador-parcelas
Short Description: Exibe uma tabela de simulação de parcelamento do Mercado Pago direto na página do produto do WooCommerce.
Pagou – Payments for WooCommerce
pagou-payments-for-woocommerce
Pagamentos via PIX e boletos bancários no WooCommerce.
PEI Digital – PIX Sandbox Gateway
pei-digital-sandbox-for-pix
Gateway PIX em sandbox para WooCommerce: simule pagamentos, QR Code e status.
MultiPay – Pagamentos e Fidelidade para WooCommerce Developer Profile
1 plugin · 10 total installs
How We Detect MultiPay – Pagamentos e Fidelidade para WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-multipay/assets/css/general.css/wp-content/plugins/wc-multipay/assets/js/general.js/wp-content/plugins/wc-multipay/assets/css/style.css/wp-content/plugins/wc-multipay/assets/js/general.jswc-multipay/assets/css/general.css?ver=wc-multipay/assets/js/general.js?ver=wc-multipay/assets/css/style.css?ver=HTML / DOM Fingerprints
wc_pay_multipay_section<!-- MultiPay payment section --><!-- End MultiPay payment section --><!-- MultiPay gateway options --><!-- End MultiPay gateway options -->data-multipay-gatewaydata-multipay-order-iddata-multipay-payment-urlwc_multipay_params/wp-json/wc-multipay-gateway/v1/create_payment