
OXXO PAY powered by Spin Security & Risk Analysis
wordpress.org/plugins/digitalfemsa-payment-gatewayWooCommerce Payment Gateway for DigitalFemsa.io: Securely process cash payments and send email notifications for successful purchases.
Is OXXO PAY powered by Spin Safe to Use in 2026?
Generally Safe
Score 100/100OXXO PAY powered by Spin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The digitalfemsa-payment-gateway plugin version 1.0.10 presents a mixed security posture. On the positive side, the static analysis indicates a lack of critical vulnerabilities such as dangerous functions, raw SQL queries, unsanitized paths in taint analysis, and external HTTP requests. The absence of known CVEs further contributes to an impression of a relatively secure plugin. However, several areas raise significant concerns. The low percentage of properly escaped output (65%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the total number of outputs analyzed. Additionally, the complete absence of nonce checks and capability checks across all entry points is a major oversight, leaving the plugin vulnerable to various forms of unauthorized actions and privilege escalation if any entry points were to be discovered or become accessible in future updates. The presence of file operations also warrants careful consideration, as these could be exploited if not properly secured.
Key Concerns
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
- File operations present
OXXO PAY powered by Spin Security Vulnerabilities
OXXO PAY powered by Spin Code Analysis
Bundled Libraries
Output Escaping
OXXO PAY powered by Spin Attack Surface
WordPress Hooks 5
Maintenance & Trust
OXXO PAY powered by Spin Maintenance & Trust
Maintenance Signals
Community Trust
OXXO PAY powered by Spin Alternatives
Conekta Payment Gateway
conekta-payment-gateway
WooCommerce Payment Gateway for Conekta.io This bundles functionality to process credit cards and cash payments securely as well as send email notific …
elegro Crypto Payment
elegro-payment
Increase your customers base by accepting cryptocurrencies.
Cashfree for WooCommerce
cashfree
Official Cashfree Payment Gateway plugin for WooCommerce.
Knit Pay – Cashfree, Instamojo, Razorpay, Paypal and more
knit-pay
Seamlessly integrates 500+ payment gateways, including Cashfree, Instamojo, PayPal, Razorpay, and SSLCommerz, with over 100 WordPress plugins.
CashBill.pl – Płatności WooCommerce
cashbill-payment-method
Dedykowane rozwiązanie integrujące najpopularniejsze metody płatności. Dzięki tej wtyczce możesz w atrakcyjny sposób prezentować siatkę z logotypami b …
OXXO PAY powered by Spin Developer Profile
1 plugin · 100 total installs
How We Detect OXXO PAY powered by Spin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/digitalfemsa-payment-gateway/images/oxxopay_b2b.svg/wp-content/plugins/digitalfemsa-payment-gateway/images/oxxopay_b2c.svgdigitalfemsa-payment-gateway/spin_checkout.php?ver=digitalfemsa-payment-gateway/spin_gateway_helper.php?ver=digitalfemsa-payment-gateway/spin_plugin.php?ver=digitalfemsa-payment-gateway/spin_block_gateway.php?ver=HTML / DOM Fingerprints
data-integration-typedata-integration-namedata-plugin-versiondata-platform-versiondata-device-typewindow.spin_obj/wp-json/digitalfemsa-payment-gateway/v1/webhook