
Iran Alves – Ebit Banner para Woocommerce Security & Risk Analysis
wordpress.org/plugins/woo-display-ebit-bannerPlugin que exibe banner ou selo Ebit com a utilização de shortcodes. Ebit é a maior plataforma de avaliação de lojas virtuais do Brasil.
Is Iran Alves – Ebit Banner para Woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100Iran Alves – Ebit Banner para Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-display-ebit-banner" plugin v0.3 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities in its history and utilizes prepared statements for all its SQL queries, which is a strong indicator of secure database interaction. The static analysis also shows no dangerous functions or external HTTP requests, and a complete absence of critical or high-severity taint flows, suggesting a generally clean codebase.
However, there are notable concerns. The plugin exhibits a low level of output escaping, with only 25% of its outputs being properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of two shortcodes which are common entry points for user-supplied data that might not be adequately sanitized before being displayed.
Furthermore, the absence of nonce and capability checks is a critical oversight. While the static analysis reports no unprotected entry points currently, the lack of these fundamental security mechanisms means that any future introduction of features that could be exploited, or any change in the plugin's interaction with WordPress core, could easily lead to unprotected actions. The vulnerability history being clean is positive, but it cannot compensate for the existing code-level weaknesses.
Key Concerns
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Iran Alves – Ebit Banner para Woocommerce Security Vulnerabilities
Iran Alves – Ebit Banner para Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Iran Alves – Ebit Banner para Woocommerce Attack Surface
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
Iran Alves – Ebit Banner para Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Iran Alves – Ebit Banner para Woocommerce Alternatives
Payment Gateway of PayPal for WooCommerce
express-checkout-paypal-payment-gateway-for-woocommerce
Enable faster checkout with PayPal for WooCommerce. Add PayPal Express/PayPal Standard gateways that accept PayPal, Pay Later, debit & credit cards.
Razorpay Payment Button Plugin
razorpay-payment-button
Start accepting payments on WordPress via credit/debit cards, UPI, wallets and more in less than five minutes. One-time and recurring payments.
Razorpay Payment Button Elementor Plugin
razorpay-payment-button-elementor
Start accepting payments on pages or blogs built on Elementor. Offer credit/debit cards, UPI, wallets and more in less than five minutes.
GoCardless for WooCommerce
woocommerce-gateway-gocardless
Extends WooCommerce with a GoCardless gateway. A GoCardless merchant account is required.
Bayarcash WooCommerce
bayarcash-wc
Accept online payment & QR from Malaysia. Currently, Bayarcash support FPX, Direct Debit and DuitNow payment channels.
Iran Alves – Ebit Banner para Woocommerce Developer Profile
4 plugins · 30 total installs
How We Detect Iran Alves – Ebit Banner para Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-display-ebit-banner/assets/css/wc-qsti-admin.cssHTML / DOM Fingerprints
plugin-aboutcol-1col-2 plugin-about data-section="wc_qsti"