Wompi Portal de Pagos Security & Risk Analysis

wordpress.org/plugins/wompi-portal-de-pagos

Pasarela de Pago de WooCommerce para Wompi

4K active installs v2.0.0 PHP 7.2+ WP 3.5.0+ Updated Dec 21, 2024
bancolombialink-de-pagopasarela-de-pagosportal-de-pagoswompi
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wompi Portal de Pagos Safe to Use in 2026?

Generally Safe

Score 92/100

Wompi Portal de Pagos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wompi-portal-de-pagos" v2.0.0 plugin exhibits a strong security posture. The absence of any recorded CVEs, critical taint flows, raw SQL queries, and a very low percentage of unescaped output indicates a developer who is mindful of security best practices. The plugin also successfully implements nonce and capability checks where appropriate, further contributing to its security. The limited attack surface with no identified unprotected entry points is a significant strength. However, the presence of file operations and external HTTP requests, while not inherently vulnerabilities, are areas that warrant careful scrutiny. These functionalities could potentially introduce risks if not handled with robust sanitization and validation, especially in the context of external integrations. Overall, the plugin appears to be secure, but these specific areas should be continuously monitored for potential future risks.

Key Concerns

  • File operations detected
  • External HTTP requests detected
  • Minor unescaped output detected (3% of outputs)
Vulnerabilities
None known

Wompi Portal de Pagos Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wompi Portal de Pagos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
35 escaped
Nonce Checks
4
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped36 total outputs
Attack Surface

Wompi Portal de Pagos Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_noticesincludes\admin\class-wc-wompi-admin-notices.php:18
actionwoocommerce_receipt_wompiincludes\class-wompi-portal-pagos-gateway-custom.php:28
actionadmin_enqueue_scriptsincludes\class-wompi-portal-pagos-main.php:69
actionwoocommerce_after_checkout_validationincludes\class-wompi-portal-pagos-main.php:72
actionwoocommerce_thankyou_order_received_textincludes\class-wompi-portal-pagos-main.php:73
actionwoocommerce_admin_order_data_after_order_detailsincludes\class-wompi-portal-pagos-main.php:74
filterwoocommerce_thankyou_order_keyincludes\class-wompi-portal-pagos-main.php:75
actioninitincludes\class-wompi-portal-pagos-order-statuses.php:18
filterwc_order_statusesincludes\class-wompi-portal-pagos-order-statuses.php:19
actionwoocommerce_process_shop_order_metaincludes\class-wompi-portal-pagos-order-statuses.php:20
actionwoocommerce_api_wc_wompiincludes\class-wompi-portal-pagos-webhook-handler.php:14
actionplugins_loadedwompi-portal-de-pagos.php:62
actionadmin_noticeswompi-portal-de-pagos.php:73
actionadmin_noticeswompi-portal-de-pagos.php:81
filterwoocommerce_payment_gatewayswompi-portal-de-pagos.php:101
actionbefore_woocommerce_initwompi-portal-de-pagos.php:129
actionwoocommerce_blocks_loadedwompi-portal-de-pagos.php:132
actionwoocommerce_blocks_payment_method_type_registrationwompi-portal-de-pagos.php:147
Maintenance & Trust

Wompi Portal de Pagos Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 21, 2024
PHP min version7.2
Downloads8K

Community Trust

Rating20/100
Number of ratings2
Active installs4K
Developer Profile

Wompi Portal de Pagos Developer Profile

Wompi

2 plugins · 5K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wompi Portal de Pagos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wompi-portal-de-pagos/assets/js/wompi-gateway.js/wp-content/plugins/wompi-portal-de-pagos/assets/css/wompi-gateway.css/wp-content/plugins/wompi-portal-de-pagos/assets/js/wompi-checkout.js
Script Paths
https://checkout.wompi.co/widget.js
Version Parameters
wompi-portal-de-pagos/assets/js/wompi-gateway.js?ver=wompi-portal-de-pagos/assets/css/wompi-gateway.css?ver=wompi-portal-de-pagos/assets/js/wompi-checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
wompi-gateway-settings
HTML Comments
Wompi Portal de PagosWompi Portal de Pagos para WooCommerce.Wompi custom gateway
Data Attributes
data-wompi-checkout-urldata-wompi-signaturedata-wompi-public-keydata-wompi-currencydata-wompi-amount-in-centsdata-wompi-reference+2 more
JS Globals
WompiGatewaySettingswompiCheckout
REST Endpoints
/wp-json/wompi/v1/webhook
FAQ

Frequently Asked Questions about Wompi Portal de Pagos