
Nexi XPay Security & Risk Analysis
wordpress.org/plugins/cartasi-x-payXPay is the payment gateway provided by Nexi, a leading group in Italy with the goal of shaping the future of digital payments.
Is Nexi XPay Safe to Use in 2026?
Generally Safe
Score 100/100Nexi XPay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cartasi-x-pay" v8.3.1 plugin exhibits significant security concerns due to a large attack surface with a high proportion of unprotected entry points. Specifically, 14 AJAX handlers and 5 REST API routes lack proper authentication or permission checks. While the plugin demonstrates good practices with SQL queries all using prepared statements and no dangerous functions are identified, the lack of output escaping on a substantial portion (66%) of outputs poses a risk of Cross-Site Scripting (XSS) vulnerabilities.
The absence of nonce checks on AJAX handlers, coupled with the unescaped outputs, creates a direct pathway for potential XSS attacks. The taint analysis, although limited, did not reveal critical or high-severity unsanitized flows, but this could be due to the limited scope of analysis or the lack of direct input to those flows. The plugin's history of zero known CVEs is a positive indicator, but it does not mitigate the immediate risks identified in the static analysis. The plugin's strengths lie in its SQL handling and lack of bundled libraries, but these are overshadowed by the critical exposure of its entry points and output handling deficiencies.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Low output escaping percentage
- Missing nonce checks on AJAX
- Unsanitized flows (though limited)
Nexi XPay Security Vulnerabilities
Nexi XPay Code Analysis
Output Escaping
Data Flow Analysis
Nexi XPay Attack Surface
AJAX Handlers 14
REST API Routes 7
WordPress Hooks 32
Scheduled Events 2
Maintenance & Trust
Nexi XPay Maintenance & Trust
Maintenance Signals
Community Trust
Nexi XPay Alternatives
Nexi XPay Build
nexi-xpay-build
XPay is the payment gateway provided by Nexi, a leading group in Italy with the goal of shaping the future of digital payments.
Instamojo for WooCommerce
woo-instamojo
Sell & collect payments instantly for almost anything -- directly from your WordPress website.
Up2pay e-Transactions WooCommerce Payment Gateway
e-transactions-wc
This plugin is a Up2pay e-Transactions payment gateway for WooCommerce 4.x
HyperPay Payments
hyperpay-gateways
Payments Gateways provided by Gate2Play, to make you able to add Credit Card, Mada, STCpay and more payments method.
Paybox WooCommerce Payment Gateway
paybox-woocommerce-gateway
This plugin is a Paybox payment gateway for WooCommerce 4.x
Nexi XPay Developer Profile
2 plugins · 6K total installs
How We Detect Nexi XPay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cartasi-x-pay/assets/js/xpay.js/wp-content/plugins/cartasi-x-pay/assets/css/xpay.css/wp-content/plugins/cartasi-x-pay/assets/js/xpay-googlepay-npg.js/wp-content/plugins/cartasi-x-pay/assets/js/xpay-googlepay.js/wp-content/plugins/cartasi-x-pay/assets/js/xpay-applepay.js/wp-content/plugins/cartasi-x-pay/assets/js/xpay-build-npg.js/wp-content/plugins/cartasi-x-pay/assets/js/xpay-build.jshttps://pay.google.com/gp/p/js/pay.jshttps://applepay.cdn-apple.com/jsapi/1.latest/apple-pay-sdk.jscartasi-x-pay/xpay.js?ver=cartasi-x-pay/xpay.css?ver=cartasi-x-pay/xpay-googlepay-npg.js?ver=cartasi-x-pay/xpay-googlepay.js?ver=cartasi-x-pay/xpay-applepay.js?ver=cartasi-x-pay/xpay-build-npg.js?ver=cartasi-x-pay/xpay-build.js?ver=HTML / DOM Fingerprints
window.xpay_checkoutwindow.xpay_googlepay_npgwindow.xpay_googlepaywindow.xpay_applepaywindow.xpay_build_npgwindow.xpay_build/wp-json/nexi-xpay/v1/s2s-notification/wp-json/nexi-xpay/v1/redirect-completion/wp-json/nexi-xpay/v1/cancel-url/wp-json/nexi-npg/v1/s2s-notification/wp-json/nexi-npg/v1/redirect-completion/wp-json/nexi-npg/v1/cancel-url