
PoloPag – Pix Automático para eCommerce Security & Risk Analysis
wordpress.org/plugins/wc-polo-paymentsAceite pagamentos via Pix e receba instantaneamente no banco de sua preferência! Instalação e configuração simples para todos.
Is PoloPag – Pix Automático para eCommerce Safe to Use in 2026?
Generally Safe
Score 98/100PoloPag – Pix Automático para eCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "wc-polo-payments" v3.0.0 plugin exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and complete output escaping are significant strengths. Furthermore, the zero unprotected entry points and the presence of a nonce check are positive indicators.
However, a critical concern arises from the plugin's vulnerability history. A previously disclosed "PHP Remote File Inclusion" vulnerability, even if currently patched, indicates a potential for severe security flaws if not diligently maintained. The presence of one historical high-severity vulnerability and the fact that the last known vulnerability was in the future (2025-07-28) suggests potential data integrity or reporting issues. The single file operation and two external HTTP requests, while not immediately critical, warrant careful review to ensure they are implemented securely and don't introduce unforeseen risks.
In conclusion, while the current version of the plugin demonstrates good secure coding practices in its static analysis, the past vulnerability, particularly the RFI type, necessitates ongoing vigilance. Developers should prioritize comprehensive security auditing and timely patching of any future vulnerabilities. The reported future vulnerability date is a significant anomaly that requires clarification and investigation.
Key Concerns
- History of PHP Remote File Inclusion vulnerability
- One historically unpatched high severity vulnerability
- External HTTP requests present
- File operations present
- Last vulnerability reported in the future
PoloPag – Pix Automático para eCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PoloPag – Pix Automático para Woocommerce <= 2.0.9 - Unauthenticated Local File Inclusion
PoloPag – Pix Automático para eCommerce Code Analysis
Output Escaping
PoloPag – Pix Automático para eCommerce Attack Surface
WordPress Hooks 5
Scheduled Events 2
Maintenance & Trust
PoloPag – Pix Automático para eCommerce Maintenance & Trust
Maintenance Signals
Community Trust
PoloPag – Pix Automático para eCommerce Alternatives
Pix por Piggly (para Woocommerce)
pix-por-piggly
Pix por Piggly v2.1.2
Pix Automático com Pagarme para WooCommerce
wc-pagarme-pix-payment
Pagamentos Pix com compensação automática, status do pedido é alterado automaticamente.
Virtuaria Serveloja
virtuaria-serveloja
Permite pagamentos com Cartão de crédito e Pix com confirmação automática na sua loja Woocommerce.
Invoice Payment Gateway for WooCommerce
wc-invoice-gateway
The Invoice Payment Gateway for WooCommerce plugin adds an Invoice Payment Gateway feature to the WooCommerce plugin for B2B transactions when instant …
ECPay Ecommerce for WooCommerce
ecpay-ecommerce-for-woocommerce
綠界科技外掛套件,提供合作特店以及個人賣家使用開放原始碼商店系統時,無須自行處理複雜的檢核,直接透過安裝設定外掛套件,便可快速介接綠界科技系統,進行金流、物流、電子發票操作。
PoloPag – Pix Automático para eCommerce Developer Profile
1 plugin · 100 total installs
How We Detect PoloPag – Pix Automático para eCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-polo-payments/assets/js/public/checkout.js/wp-content/plugins/wc-polo-payments/assets/js/public/before-checkout.js/wp-content/plugins/wc-polo-payments/assets/js/public/checkout.js/wp-content/plugins/wc-polo-payments/assets/js/public/before-checkout.jswc-polo-payments/assets/js/public/checkout.js?ver=wc-polo-payments/assets/js/public/before-checkout.js?ver=HTML / DOM Fingerprints
data-polopagpayments-initpolopagpayments_geteway