
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Security & Risk Analysis
wordpress.org/plugins/woo-redePayment Gateway for Rede Itaú for WooCommerce - PIX, Credit Card and Debit Cards.
Is Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Safe to Use in 2026?
Generally Safe
Score 98/100Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit has a strong security track record. Known vulnerabilities have been patched promptly.
The "woo-rede" plugin v5.3.3 exhibits a concerning security posture primarily due to its large, unprotected attack surface. While the code demonstrates good practices like 100% prepared SQL statements and a high percentage of output escaping, the significant number of unprotected AJAX handlers and REST API routes presents a considerable risk. These entry points, if vulnerable to injection or manipulation, could be exploited by unauthenticated users, leading to unauthorized actions or data breaches.
The taint analysis, while limited, did reveal one flow with unsanitized paths, which is a potential concern for path traversal or file inclusion vulnerabilities, though it was not categorized as critical or high severity. The vulnerability history shows two past medium severity CVEs, including "Missing Authentication for Critical Function" and "Insufficient Verification of Data Authenticity." The fact that the last vulnerability was recorded in 2026 suggests potential for outdated security practices or a lack of ongoing maintenance, even though there are currently no unpatched CVEs.
In conclusion, the plugin's strengths lie in its secure handling of SQL queries and output. However, the overwhelming majority of its attack surface is exposed without authentication, creating a significant risk profile. The historical vulnerability types further highlight the need for robust authentication and input validation on all public-facing endpoints. The plugin is not recommended for production environments without significant security hardening.
Key Concerns
- High number of unprotected AJAX handlers
- High number of unprotected REST API routes
- Taint flow with unsanitized paths
- Past medium severity CVEs
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.5 - Missing Authorization to Unauthenticated Rede Order Logs Deletion
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Unauthenticated Order Status Manipulation
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Attack Surface
AJAX Handlers 15
REST API Routes 7
WordPress Hooks 50
Scheduled Events 1
Maintenance & Trust
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Maintenance & Trust
Maintenance Signals
Community Trust
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Alternatives
Virtuaria Rede ( Itaú ) Pagamentos
virtuaria-eredeitau
Pagamentos via Pix e Cartão de Crédito na sua loja virtual com a confiabilidade da Rede / Itaú diretamente em seu WooCommerce.
PagHiper Boleto e PIX para WooCommerce
woo-boleto-paghiper
Ofereça a seus clientes pagamento boleto bancário com a PagHiper. Fácil, prático e rapido!
CIELO API PIX, credit card, debit payment for WooCommerce
lkn-wc-gateway-cielo
Payment Gateway for Cielo API for WooCommerce - PIX, Google Pay, Credit Card and Debit Cards.
Pix Automático com Pagarme para WooCommerce
wc-pagarme-pix-payment
Pagamentos Pix com compensação automática, status do pedido é alterado automaticamente.
iPag Pagamentos Digitais
ipag-woocommerce
Facilite pagamentos online com segurança e rapidez, integrando sua loja ao nosso gateway e PSP.
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Developer Profile
18 plugins · 5K total installs
How We Detect Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-rede/css/lkn-integration-rede-for-woocommerce-admin.css/wp-content/plugins/woo-rede/js/lkn-integration-rede-for-woocommerce-admin-pro-fields.js/wp-content/plugins/woo-rede/js/lkn-integration-rede-for-woocommerce-admin-pro-installments.js/wp-content/plugins/woo-rede/js/lkn-integration-rede-for-woocommerce-admin.jsjs/lkn-integration-rede-for-woocommerce-admin-pro-fields.jsjs/lkn-integration-rede-for-woocommerce-admin-pro-installments.jsjs/lkn-integration-rede-for-woocommerce-admin.jswoo-rede/css/lkn-integration-rede-for-woocommerce-admin.css?ver=woo-rede/js/lkn-integration-rede-for-woocommerce-admin-pro-fields.js?ver=woo-rede/js/lkn-integration-rede-for-woocommerce-admin-pro-installments.js?ver=woo-rede/js/lkn-integration-rede-for-woocommerce-admin.js?ver=HTML / DOM Fingerprints
lknPhpProFieldsVariableslknPhpVariables