WP28 Pague com Pix Security & Risk Analysis

wordpress.org/plugins/wp28-pague-com-pix

Add Pix as WooCommerce payment method. Adiciona ao WooCommerce o método de pagamento Pix

30 active installs v1.0.1 PHP 7.3+ WP 5.5+ Updated May 26, 2021
discountpaymentpixwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP28 Pague com Pix Safe to Use in 2026?

Generally Safe

Score 85/100

WP28 Pague com Pix has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "wp28-pague-com-pix" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of exposed AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly reduces its attack surface. Furthermore, the code demonstrates good practices with 100% of SQL queries utilizing prepared statements and a high rate of output escaping (94%), indicating a conscious effort to prevent common web vulnerabilities like SQL injection and cross-site scripting. The lack of file operations and external HTTP requests further limits potential risks.

However, the analysis does reveal some areas for improvement. The plugin has zero nonce checks and zero capability checks on its limited entry points. While the current attack surface is zero, if any new entry points are introduced or if the existing capability checks are insufficient, this could become a significant weakness. The absence of any taint analysis results is also noteworthy; while this could mean no critical issues were found, it might also indicate a limitation in the analysis tool or the scope of the analysis performed. The plugin also has no recorded vulnerability history, which is a positive sign of past security diligence, but doesn't guarantee future immunity.

In conclusion, the plugin appears to be well-developed from a security perspective for its current version, with a minimal attack surface and good handling of sensitive operations like database queries and output. The primary concern lies in the complete absence of nonce and capability checks on its limited entry points, which, although currently low risk due to the lack of entry points, represents a potential vulnerability if the plugin evolves. The clean vulnerability history is a strong positive indicator.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

WP28 Pague com Pix Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP28 Pague com Pix Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
76 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

94% escaped81 total outputs
Attack Surface

WP28 Pague com Pix Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitsrc\Includes\Core\Controller.php:95
filterwoocommerce_payment_gatewayssrc\Includes\Core\Controller.php:96
filterwoocommerce_available_payment_gatewayssrc\Includes\Core\Controller.php:98
filterwoocommerce_coupons_enabledsrc\Includes\Pix\PixDiscount.php:65
actionwoocommerce_calculate_totalssrc\Includes\Pix\PixDiscount.php:114
filterwoocommerce_gateway_titlesrc\Includes\Pix\PixDiscount.php:115
actionwoocommerce_checkout_order_processedsrc\Includes\Pix\PixDiscount.php:116
actionwoocommerce_email_before_order_tablesrc\Includes\Pix\PixGateway.php:362
actionwoocommerce_order_details_after_order_tablesrc\Includes\Pix\PixGateway.php:364
actionadmin_initsrc\Pix.php:25
actionadmin_noticessrc\Pix.php:50
actionplugins_loadedwp28-pague-com-pix.php:34
Maintenance & Trust

WP28 Pague com Pix Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 26, 2021
PHP min version7.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

WP28 Pague com Pix Developer Profile

Guilherme Pereira

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP28 Pague com Pix

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp28-pague-com-pix/src/Assets/js/settings-page.min.js/wp-content/plugins/wp28-pague-com-pix/src/Assets/js/jquery.mask.min.js/wp-content/plugins/wp28-pague-com-pix/src/Assets/js/checkout-reload.min.js/wp-content/plugins/wp28-pague-com-pix/src/Assets/js/pix-order-page.min.js/wp-content/plugins/wp28-pague-com-pix/src/Assets/css/pix-table.min.css
Script Paths
src/Assets/js/settings-page.min.jssrc/Assets/js/jquery.mask.min.jssrc/Assets/js/checkout-reload.min.jssrc/Assets/js/pix-order-page.min.js
Version Parameters
wp28-pague-com-pix/src/Assets/js/settings-page.min.js?ver=wp28-pague-com-pix/src/Assets/js/jquery.mask.min.js?ver=wp28-pague-com-pix/src/Assets/js/checkout-reload.min.js?ver=wp28-pague-com-pix/src/Assets/js/pix-order-page.min.js?ver=wp28-pague-com-pix/src/Assets/css/pix-table.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp28-pix-table
Data Attributes
data-plugin-name="wp28-pague-com-pix"
JS Globals
window.wp28PixCheckout
FAQ

Frequently Asked Questions about WP28 Pague com Pix