Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-transbank-webpay-plus-rest

Vende con las tarjetas de Webpay Plus en tu carro de compras con WooCommerce. Medio de Pago de Transbank.

0 active installs v2021.03.22 PHP + WP 4.0+ Updated Mar 21, 2021
chilepayment-gatewaytransbankwebpaywoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of "wc-transbank-webpay-plus-rest" v2021.03.22 reveals a generally positive security posture in terms of its direct attack surface and SQL handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, limiting potential direct exploitation vectors. Furthermore, all SQL queries are confirmed to use prepared statements, mitigating the risk of SQL injection vulnerabilities in that area. The plugin also exhibits no known vulnerabilities in its history, suggesting a good track record.

However, the analysis also highlights critical areas for concern. A striking 100% of output operations are not properly escaped. This lack of output escaping is a major security flaw, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin that is not properly sanitized before being rendered in the browser could be exploited by attackers to inject malicious scripts, leading to session hijacking, credential theft, or defacement.

While the plugin's direct attack surface is small and SQL queries are secure, the pervasive issue with output escaping presents a significant risk. The presence of bundled libraries, Guzzle and TCPDF v1.0, could also pose a risk if they are outdated and contain known vulnerabilities, though this is not explicitly stated. The vulnerability history is clean, which is positive, but it does not negate the immediate risks identified in the code analysis.

Key Concerns

  • Unescaped output
  • Bundled outdated library (TCPDF v1.0)
Vulnerabilities
None known

Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

GuzzleTCPDF1.0

SQL Query Safety

100% prepared7 total queries

Output Escaping

0% escaped12 total outputs
Attack Surface

Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedwc-transbank-webpay-plus-rest.php:25
actionadmin_initwc-transbank-webpay-plus-rest.php:30
filterwoocommerce_payment_gatewayswc-transbank-webpay-plus-rest.php:31
actionwoocommerce_before_cartwc-transbank-webpay-plus-rest.php:32
actioninitwc-transbank-webpay-plus-rest.php:38
actionwoocommerce_thankyouwc-transbank-webpay-plus-rest.php:108
actionadmin_enqueue_scriptswc-transbank-webpay-plus-rest.php:113
actionwoocommerce_sections_checkoutwc-transbank-webpay-plus-rest.php:114
Maintenance & Trust

Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 21, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce Developer Profile

Andrés Reyes Galgani

5 plugins · 4K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-transbank-webpay-plus-rest/build/app.js/wp-content/plugins/wc-transbank-webpay-plus-rest/build/app.css
Script Paths
/wp-content/plugins/wc-transbank-webpay-plus-rest/build/app.js
Version Parameters
wc-transbank-webpay-plus-rest/build/app.js?ver=wc-transbank-webpay-plus-rest/build/app.css?ver=

HTML / DOM Fingerprints

CSS Classes
transbank_webpay_plus_rest_buttontransbank_webpay_plus_rest_button_submit
HTML Comments
<!-- WC_Gateway_Transbank_Webpay_Plus_REST --><!-- Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce -->
Data Attributes
data-transbank-commerce-codedata-transbank-api-key
JS Globals
window.wc_transbank_webpay_plus_rest_params
REST Endpoints
/wp-json/wc-transbank-webpay-plus-rest/v1/process-payment
FAQ

Frequently Asked Questions about Migración de Medio de Pago Webpay Plus SOAP a REST de Transbank para WooCommerce