
FLEX Gold Security & Risk Analysis
wordpress.org/plugins/flex-gold-for-woocommerceAdds FLEX Gold as a payment method in woocommerce, more info here.
Is FLEX Gold Safe to Use in 2026?
Generally Safe
Score 85/100FLEX Gold has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'flex-gold-for-woocommerce' v2.7.10 exhibits a mixed security posture. On the positive side, there are no reported vulnerabilities (CVEs), and the plugin utilizes prepared statements for all its SQL queries, which is a significant security strength. The absence of known vulnerabilities and the use of secure database practices suggest a generally well-maintained plugin. However, the static analysis reveals several concerning areas. Notably, the lack of any nonce checks or capability checks on the limited entry points presents a significant risk. While the attack surface is currently reported as zero, this could change with future updates, and the absence of these fundamental security measures makes any future additions inherently insecure. Furthermore, the presence of 'ini_set' and file operations without clear sanitization, coupled with four taint flows identified with unsanitized paths, points to potential for insecure handling of data, particularly concerning file paths. The code also shows a significant percentage of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Flows with unsanitized paths
- Improperly escaped output
- Dangerous function ini_set usage
FLEX Gold Security Vulnerabilities
FLEX Gold Release Timeline
FLEX Gold Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
FLEX Gold Attack Surface
WordPress Hooks 12
Maintenance & Trust
FLEX Gold Maintenance & Trust
Maintenance Signals
Community Trust
FLEX Gold Alternatives
Gold-Price
gold-price-based-on-weight
Automatically calculate WooCommerce product prices based on a global price per gram of Gold, Silver, or Platinum and the weight of each product.
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
WooCommerce Stripe Payment Gateway
woocommerce-gateway-stripe
Accept debit and credit cards in 135+ currencies, many local methods like Alipay, ACH, and SEPA, and express checkout with Apple Pay and Google Pay.
WooCommerce Tax (formerly WooCommerce Shipping & Tax)
woocommerce-services
We’re here to help with tax rates: collect accurate sales tax, automatically.
FLEX Gold Developer Profile
1 plugin · 10 total installs
How We Detect FLEX Gold
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flex-gold-for-woocommerce/assets/css/checkout.css/wp-content/plugins/flex-gold-for-woocommerce/assets/js/checkout.js/wp-content/plugins/flex-gold-for-woocommerce/assets/js/checkout.min.js/wp-content/plugins/flex-gold-for-woocommerce/assets/js/wc-dg-capital-gateway.js/wp-content/plugins/flex-gold-for-woocommerce/assets/js/checkout.js/wp-content/plugins/flex-gold-for-woocommerce/assets/js/checkout.min.js/wp-content/plugins/flex-gold-for-woocommerce/assets/js/wc-dg-capital-gateway.jsflex-gold-for-woocommerce/assets/css/checkout.css?ver=flex-gold-for-woocommerce/assets/js/checkout.js?ver=flex-gold-for-woocommerce/assets/js/checkout.min.js?ver=flex-gold-for-woocommerce/assets/js/wc-dg-capital-gateway.js?ver=HTML / DOM Fingerprints
wc_payment_methodpayment_boxdg-capital-plugin-settings<!-- The Woocommerce gateway class --><!-- The Woocommerce gateway class --><!-- BEGIN DUMMY CONTENT FOR ADDING GATEWAY -->data-gateway_iddata-gateway_namedata-is_disableddata-is_test_modedata-dg-capital-plugin-enableddata-dg-capital-plugin-payment-mode+17 moredg_capital_gateway_params