BUX.digital Payment Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/bux-digital-gateway

This plugin implements a payment gateway for WooCommerce to let buyers pay with BUX tokens on eCash, via PayPal or Credit Card.

0 active installs v1.0.3 PHP + WP 3.7.0+ Updated Dec 3, 2022
bitcoinbuxcryptocurrencyecashwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BUX.digital Payment Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

BUX.digital Payment Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "bux-digital-gateway" v1.0.3 exhibits a mixed security posture. On one hand, the static analysis shows a strong adherence to good security practices, with no identified dangerous functions, all SQL queries using prepared statements, and a good percentage of output escaping. The complete absence of known CVEs and a clean vulnerability history further suggest a well-maintained codebase in terms of publicly known flaws.

However, significant concerns arise from the lack of security checks. The total absence of nonce checks and capability checks, coupled with zero protected entry points (AJAX, REST API, shortcodes, cron), indicates a wide-open attack surface. While the taint analysis did not reveal critical or high-severity unsanitized paths, the fact that all three analyzed flows have unsanitized paths is a red flag. This suggests potential for various injection vulnerabilities if an attacker can control input that feeds into these flows, even if they are not currently exploitable in a critical way. The presence of file operations and external HTTP requests without any explicit security checks also warrants caution.

In conclusion, while "bux-digital-gateway" v1.0.3 benefits from a clean vulnerability history and good practices regarding SQL and most output escaping, its critical lack of authentication and authorization checks across all its potential entry points presents a substantial risk. The taint analysis, though not critical, highlights potential weaknesses that could be exploited with carefully crafted inputs.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • All analyzed taint flows have unsanitized paths
  • File operations without explicit checks
  • External HTTP requests without explicit checks
  • Low percentage of properly escaped output (80%)
Vulnerabilities
None known

BUX.digital Payment Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BUX.digital Payment Gateway for WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

BUX.digital Payment Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

80% escaped10 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
bux_gateway_load (class-wc-gateway-bux.php:27)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BUX.digital Payment Gateway for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedclass-wc-gateway-bux.php:26
filterwoocommerce_payment_gatewaysclass-wc-gateway-bux.php:37
actionwoocommerce_receipt_buxclass-wc-gateway-bux.php:87
actionwoocommerce_api_wc_gateway_buxclass-wc-gateway-bux.php:91
Maintenance & Trust

BUX.digital Payment Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 3, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

BUX.digital Payment Gateway for WooCommerce Developer Profile

Badger LLC

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BUX.digital Payment Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bux-digital-gateway/assets/images/icons/bux.png

HTML / DOM Fingerprints

REST Endpoints
wc-api/WC_Gateway_BUX
FAQ

Frequently Asked Questions about BUX.digital Payment Gateway for WooCommerce