Crypto payment checkout by intrXn Security & Risk Analysis

wordpress.org/plugins/crypto-payment-checkout-by-intrxn

Crypto payment checkout by intrXn. The best way to accept cryptocurrencies.

0 active installs v1.0 PHP 5.6+ WP 5.0+ Updated Sep 21, 2022
bitcoincrocryptocryptocurrencypayments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Crypto payment checkout by intrXn Safe to Use in 2026?

Generally Safe

Score 85/100

Crypto payment checkout by intrXn has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The crypto-payment-checkout-by-intrxn v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and generally escaping output, with 75% of outputs being properly handled. The absence of dangerous functions, file operations, and bundled libraries further contributes to a cleaner codebase. Furthermore, there is no recorded vulnerability history, suggesting a potentially stable and well-maintained component up to this version.

However, significant security concerns are present due to the plugin's attack surface. The most critical finding is a single unprotected REST API route. This exposes a potential entry point that could be exploited by unauthenticated users, leading to unintended actions or data exposure. The lack of nonce checks and capability checks on this and any other potential entry points is a major weakness. The taint analysis showing zero flows is positive but does not mitigate the risk posed by the unprotected REST API, as taint analysis often requires specific vulnerable code patterns that may not be present, yet the entry point itself is inherently risky.

In conclusion, while the plugin shows strengths in secure coding practices like prepared statements and output escaping, the presence of an unprotected REST API route is a severe vulnerability. This unprotected entry point, combined with the absence of capability checks and nonces, significantly elevates the risk profile of this plugin, despite its clean vulnerability history and lack of dangerous code constructs. Developers should prioritize securing this REST API route.

Key Concerns

  • Unprotected REST API route
  • REST API route without permission callbacks
  • No nonce checks
  • No capability checks
  • 3 out of 4 outputs not properly escaped
Vulnerabilities
None known

Crypto payment checkout by intrXn Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Crypto payment checkout by intrXn Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 17, 2026

Crypto payment checkout by intrXn Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface
1 unprotected

Crypto payment checkout by intrXn Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

POST/wp-json/intrxn-pay/v1/webhookclass-intrxn-pay.php:74
WordPress Hooks 8
filterhttp_request_timeoutclass-intrxn-pay.php:21
actionadmin_initclass-intrxn-pay.php:43
filterplugin_action_linksclass-intrxn-pay.php:57
actionplugins_loadedclass-intrxn-pay.php:70
actionrest_api_initclass-intrxn-pay.php:73
actionadmin_noticesclass-intrxn-pay.php:106
filterwoocommerce_payment_gatewaysclass-intrxn-pay.php:537
filterwoocommerce_order_data_store_cpt_get_orders_queryclass-intrxn-pay.php:555
Maintenance & Trust

Crypto payment checkout by intrXn Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 21, 2022
PHP min version5.6
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Crypto payment checkout by intrXn Developer Profile

intrxn

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Crypto payment checkout by intrXn

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crypto-payment-checkout-by-intrxn/assets/logo.png

HTML / DOM Fingerprints

CSS Classes
environment-select
Data Attributes
data-environment
REST Endpoints
/wp-json/intrxn-pay/v1/webhook
FAQ

Frequently Asked Questions about Crypto payment checkout by intrXn