
BNPLX Payment Gateway for WooCommerce Security & Risk Analysis
wordpress.org/plugins/bnplx-payment-gateway-for-woocommerceOptimal BNPL Solutions for Merchants | bnplx.io
Is BNPLX Payment Gateway for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100BNPLX Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `bnplx-payment-gateway-for-woocommerce` plugin version 1.1.0 exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in areas like SQL query sanitization, output escaping, and a clean vulnerability history, the lack of authentication on all identified AJAX entry points presents a substantial risk. This means any unauthenticated user could potentially interact with these handlers, leading to various security issues if the functionality they trigger is sensitive or can be manipulated.
The static analysis did not reveal any dangerous functions, unsanitized taint flows, or file operations, which are positive indicators. However, the presence of 6 AJAX handlers without any authentication checks is the most critical finding. Although only 3 nonces and 1 capability check were identified, they are not applied to all AJAX handlers, leaving a large portion of the attack surface exposed. The vulnerability history shows no recorded CVEs, which suggests that this specific version, or past versions, might not have had publicly known vulnerabilities. This could indicate diligent security practices or simply a lack of discovery.
In conclusion, while the plugin has strengths in its handling of SQL and output, the unprotected AJAX endpoints represent a significant security weakness. The absence of mandatory authentication on these handlers is a serious oversight that could be exploited. Further investigation into the functionality exposed by these AJAX handlers is crucial to fully understand the potential impact of this exposure.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth
- Limited nonce checks compared to entry points
- Limited capability checks compared to entry points
BNPLX Payment Gateway for WooCommerce Security Vulnerabilities
BNPLX Payment Gateway for WooCommerce Code Analysis
Output Escaping
BNPLX Payment Gateway for WooCommerce Attack Surface
AJAX Handlers 6
WordPress Hooks 12
Maintenance & Trust
BNPLX Payment Gateway for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
BNPLX Payment Gateway for WooCommerce Alternatives
Payflex Payment Gateway
payflex-payment-gateway
The Payflex extension for WooCommerce enables you to accept payments in installments via one of South Africa’s most popular payment gateways.
seQura
sequra
Flexible payment platform that enhances business conversion and recurrence. The easiest, safest, and quickest way for customers to pay installments.
Klump WooCommerce Buy Now, Pay Later Plugin
klump-wc-payment-gateway
Klump WooCommerce Buy Now, Pay Later plugin allows merchants to give their customers the option of purchasing an item or service and make payment in f …
AhaPay Buy Now Pay Later
ahapay-buy-now-pay-later
AhaPay Buy Now Pay Later AhaPay is a Buy Now Pay Later (BNPL) payment solution that enables customers to split their purchases into installments with …
Payment Gateway Based Fees and Discounts for WooCommerce
checkout-fees-for-woocommerce
Set fees and discounts for WooCommerce payment gateways.
BNPLX Payment Gateway for WooCommerce Developer Profile
1 plugin · 0 total installs
How We Detect BNPLX Payment Gateway for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bnplx-payment-gateway-for-woocommerce/assets/js/frontend/noBlocks.js/wp-content/plugins/bnplx-payment-gateway-for-woocommerce/assets/js/frontend/noBlocks.css/wp-content/plugins/bnplx-payment-gateway-for-woocommerce/assets/js/frontend/noBlocks.js/wp-content/plugins/bnplx-payment-gateway-for-woocommerce/assets/js/frontend/noBlocks.css?ver=HTML / DOM Fingerprints
wc_bnplx_gateway_block_supportwc_bnplx_gateway_hpos_supportWC_BNPLX_Admin_CheckerWC_BNPLX_Payments<!-- BNPLX Payment gateway class. --><!-- BNPLX Payment gateway class. --><!-- Registers WooCommerce Blocks integration. --><!-- HPOS compatibility -->+2 moredata-gateway-id="bnplx"data-payment-methods="bnplx"bnplx