Iran Alves – Ebit Banner para Woocommerce Security & Risk Analysis

wordpress.org/plugins/woo-display-ebit-banner

Plugin que exibe banner ou selo Ebit com a utilização de shortcodes. Ebit é a maior plataforma de avaliação de lojas virtuais do Brasil.

20 active installs v0.3 PHP 5.6+ WP 3.9.23+ Updated Unknown
avaliacao-de-pedidoavaliacao-ebitbanner-ebitebitplugin-ebit
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Iran Alves – Ebit Banner para Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Iran Alves – Ebit Banner para Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "woo-display-ebit-banner" plugin v0.3 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities in its history and utilizes prepared statements for all its SQL queries, which is a strong indicator of secure database interaction. The static analysis also shows no dangerous functions or external HTTP requests, and a complete absence of critical or high-severity taint flows, suggesting a generally clean codebase.

However, there are notable concerns. The plugin exhibits a low level of output escaping, with only 25% of its outputs being properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of two shortcodes which are common entry points for user-supplied data that might not be adequately sanitized before being displayed.

Furthermore, the absence of nonce and capability checks is a critical oversight. While the static analysis reports no unprotected entry points currently, the lack of these fundamental security mechanisms means that any future introduction of features that could be exploited, or any change in the plugin's interaction with WordPress core, could easily lead to unprotected actions. The vulnerability history being clean is positive, but it cannot compensate for the existing code-level weaknesses.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Iran Alves – Ebit Banner para Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Iran Alves – Ebit Banner para Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wc_qsti_save_config (inc\class-wc-qsti-admin.php:215)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Iran Alves – Ebit Banner para Woocommerce Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wc_qsti_ebit_banner] inc\class-wc-qsti-banner.php:102
[wc_qsti_ebit_selo] inc\class-wc-qsti-banner.php:105
WordPress Hooks 7
filterwoocommerce_order_data_store_cpt_get_orders_queryinc\class-wc-qsti-banner.php:80
actionadmin_noticesinc\class-wc-qsti-banner.php:87
filterwoocommerce_get_sections_productsinc\class-wc-qsti-banner.php:90
filterwoocommerce_get_settings_productsinc\class-wc-qsti-banner.php:93
actionwoocommerce_update_options_productsinc\class-wc-qsti-banner.php:96
actionadmin_headinc\class-wc-qsti-banner.php:99
actionwp_footerinc\class-wc-qsti-banner.php:330
Maintenance & Trust

Iran Alves – Ebit Banner para Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedUnknown
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings4
Active installs20
Developer Profile

Iran Alves – Ebit Banner para Woocommerce Developer Profile

iranalves85

4 plugins · 30 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Iran Alves – Ebit Banner para Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-display-ebit-banner/assets/css/wc-qsti-admin.css

HTML / DOM Fingerprints

CSS Classes
plugin-aboutcol-1col-2
HTML Comments
plugin-about
Data Attributes
data-section="wc_qsti"
FAQ

Frequently Asked Questions about Iran Alves – Ebit Banner para Woocommerce