
Efí Bank Security & Risk Analysis
wordpress.org/plugins/woo-gerencianet-officialReceba pagamentos por Boleto bancário, Pix, Cartão de Crédito, Open Finance, Assinaturas via Boleto e/ou Cartão de Crédito em sua loja WooCommerce com …
Is Efí Bank Safe to Use in 2026?
Mostly Safe
Score 74/100Efí Bank is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The "woo-gerencianet-official" plugin v3.1.3 presents a significant security risk due to a large attack surface comprised entirely of unprotected AJAX handlers. While the code shows some positive signs like 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, the lack of authorization checks on all AJAX endpoints is a major concern. This could allow unauthorized users to trigger plugin functionalities, potentially leading to unintended actions or information exposure.
The taint analysis, while not revealing critical or high severity issues, did find 7 flows with unsanitized paths. This, combined with the unprotected AJAX handlers, suggests a potential for path traversal vulnerabilities or other file-related exploits. The plugin's history of 3 medium severity vulnerabilities, including Exposure of Sensitive Information, CSRF, and Missing Authorization, further reinforces the pattern of authorization and input validation weaknesses. The presence of an unpatched CVE, even if medium severity, is a direct and actionable risk that requires immediate attention.
In conclusion, the plugin has some good development practices regarding database interactions and output sanitization. However, the critical flaw of unprotected AJAX endpoints, coupled with historical vulnerabilities and taint analysis findings, creates a substantial security risk. The unpatched CVE is a particularly pressing issue that needs to be addressed promptly to mitigate known exploits. The overall security posture is concerning due to these critical weaknesses.
Key Concerns
- All AJAX handlers lack authorization checks
- 7 flows with unsanitized paths found
- 1 unpatched CVE (medium severity)
- History of Missing Authorization vulnerabilities
- History of CSRF vulnerabilities
- History of Exposure of Sensitive Information vulnerabilities
- Only 1 nonce check for 8 AJAX handlers
- Only 1 capability check for 8 AJAX handlers
- Bundled Guzzle library
Efí Bank Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Gerencianet Oficial <= 3.1.3 - Unauthenticated Information Exposure
Gerencianet Oficial <= 1.4.8 - Cross-Site Request Forgery
Gerencianet Oficial <= 1.4.8 - Missing Authorization
Efí Bank Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Efí Bank Attack Surface
AJAX Handlers 8
WordPress Hooks 40
Maintenance & Trust
Efí Bank Maintenance & Trust
Maintenance Signals
Community Trust
Efí Bank Alternatives
Pix por Piggly (para Woocommerce)
pix-por-piggly
Pix por Piggly v2.1.2
OpenPix for WooCommerce
openpix-for-woocommerce
Accept Pix payments with real-time updates and seamless checkout.
Pix Automático com Pagarme para WooCommerce
wc-pagarme-pix-payment
Pagamentos Pix com compensação automática, status do pedido é alterado automaticamente.
WP28 Pague com Pix
wp28-pague-com-pix
Add Pix as WooCommerce payment method. Adiciona ao WooCommerce o método de pagamento Pix
Parcelow
parcelow
Payment method that can be easily integrated
Efí Bank Developer Profile
1 plugin · 500 total installs
How We Detect Efí Bank
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-gerencianet-official/assets/css/gerencianet-styles.css/wp-content/plugins/woo-gerencianet-official/assets/css/gerencianet-checkout-styles.css/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-checkout.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-pix.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-card-form.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-assinaturas.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-admin.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-checkout.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-pix.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-card-form.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-assinaturas.js/wp-content/plugins/woo-gerencianet-official/assets/js/gerencianet-admin.jswoo-gerencianet-official/assets/css/gerencianet-styles.css?ver=woo-gerencianet-official/assets/css/gerencianet-checkout-styles.css?ver=woo-gerencianet-official/assets/js/gerencianet-checkout.js?ver=woo-gerencianet-official/assets/js/gerencianet-pix.js?ver=woo-gerencianet-official/assets/js/gerencianet-card-form.js?ver=woo-gerencianet-official/assets/js/gerencianet-assinaturas.js?ver=woo-gerencianet-official/assets/js/gerencianet-admin.js?ver=HTML / DOM Fingerprints
gerencianet-pix-qrcodegerencianet-pix-copy-codegerencianet-pix-codegerencianet-pix-formgerencianet-card-numbergerencianet-card-expirygerencianet-card-cvcgerencianet-card-holder+7 more<!-- PIX Fields --><!-- card Fields --><!-- Assinaturas Fields --><!-- Gerencianet Payment Options -->+4 moredata-gn-pix-qrcode-urldata-gn-pix-codedata-gn-card-form-endpointdata-gn-signature-form-endpointdata-gn-admin-ajax-urlgerencianet_checkout_paramsgerencianet_pix_paramsgerencianet_card_form_paramsgerencianet_assinaturas_paramsGN_AJAX_URL/wp-json/gerencianet-oficial/v1/pix-payment-status[gerencianet_pix_qrcode][gerencianet_pix_copy_code][gerencianet_boleto_details][gerencianet_card_form]