Flux Payments Gateway for WooCommerce Security & Risk Analysis

wordpress.org/plugins/flux-payments-gateway

Accept credit cards, ACH, and cryptocurrency payments with recurring billing, invoicing, and business integrations for US and Canadian merchants.

0 active installs v1.7.2 PHP 7.4+ WP 5.0+ Updated Dec 1, 2025
achcredit-cardcryptopaymentswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flux Payments Gateway for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Flux Payments Gateway for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "flux-payments-gateway" plugin version 1.7.2 exhibits a generally positive security posture, with strong adherence to secure coding practices in several key areas. The absence of any recorded vulnerabilities, including critical or high severity issues, is a significant strength. Furthermore, the plugin demonstrates excellent output escaping, 100% prepared statement usage for SQL queries, and a solid number of nonce checks. However, a notable concern exists due to the presence of one unprotected AJAX handler, which represents a potential entry point for unauthorized actions if not properly validated or restricted by the application context.

The static analysis reveals a relatively small attack surface, with the main point of concern being the single AJAX handler lacking explicit authentication checks. Taint analysis shows no critical or high severity flows, indicating that data processed by the plugin is likely handled safely from a path traversal or injection perspective. The plugin's history of zero CVEs further supports a perception of a well-maintained and secure codebase up to this version. While the overall security is strong, the unprotected AJAX handler warrants attention as a potential weakness that could be exploited in specific scenarios.

Key Concerns

  • AJAX handler without auth checks
Vulnerabilities
None known

Flux Payments Gateway for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Flux Payments Gateway for WooCommerce Release Timeline

v1.7.2Current
v1.7.1
v1.7.0
v1.6.0
v1.5.0
v1.4.0
v1.3.0
v1.2.0
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Flux Payments Gateway for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
4
Capability Checks
1
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
init_flux_gateway_class (fluxpayments-gateway.php:17)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Flux Payments Gateway for WooCommerce Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 3

authwp_ajax_flux_sync_productsfluxpayments-gateway.php:825
authwp_ajax_flux_create_cart_orderfluxpayments-gateway.php:1006
noprivwp_ajax_flux_create_cart_orderfluxpayments-gateway.php:1007
WordPress Hooks 26
actionplugins_loadedfluxpayments-gateway.php:15
actionwp_enqueue_scriptsfluxpayments-gateway.php:52
actionwoocommerce_update_productfluxpayments-gateway.php:86
actionwoocommerce_api_flux_gateway_responsefluxpayments-gateway.php:88
filterwoocommerce_payment_gatewaysfluxpayments-gateway.php:733
filterwoocommerce_checkout_fieldsfluxpayments-gateway.php:741
actionwpfluxpayments-gateway.php:750
filterwoocommerce_cart_needs_shippingfluxpayments-gateway.php:755
filterwoocommerce_cart_needs_shipping_addressfluxpayments-gateway.php:756
filterwoocommerce_checkout_show_shippingfluxpayments-gateway.php:757
filterwoocommerce_checkout_show_billingfluxpayments-gateway.php:758
actiontemplate_redirectfluxpayments-gateway.php:762
actionadmin_enqueue_scriptsfluxpayments-gateway.php:807
actionwp_enqueue_scriptsfluxpayments-gateway.php:835
filterwoocommerce_order_button_textfluxpayments-gateway.php:865
filterwoocommerce_order_button_htmlfluxpayments-gateway.php:869
actionwpfluxpayments-gateway.php:874
filterwoocommerce_coupons_enabledfluxpayments-gateway.php:882
actionwpfluxpayments-gateway.php:885
filterwoocommerce_checkout_coupon_messagefluxpayments-gateway.php:891
actionwp_headfluxpayments-gateway.php:894
actionadmin_initfluxpayments-gateway.php:923
filterwc_coupons_enabledfluxpayments-gateway.php:929
filterwoocommerce_cart_totals_coupon_htmlfluxpayments-gateway.php:930
filterwoocommerce_cart_totals_coupon_labelfluxpayments-gateway.php:931
actionwoocommerce_proceed_to_checkoutfluxpayments-gateway.php:934
Maintenance & Trust

Flux Payments Gateway for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 1, 2025
PHP min version7.4
Downloads403

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Flux Payments Gateway for WooCommerce Developer Profile

nickkreissler59

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flux Payments Gateway for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flux-payments-gateway/assets/flux-paynow.css/wp-content/plugins/flux-payments-gateway/assets/flux-paynow.js/wp-content/plugins/flux-payments-gateway/assets/logo.png/wp-content/plugins/flux-payments-gateway/assets/flux-icon.svg
Script Paths
/wp-content/plugins/flux-payments-gateway/assets/flux-paynow.js
Version Parameters
flux-payments-gateway/assets/flux-paynow.css?ver=1.0.0flux-payments-gateway/assets/flux-paynow.js?ver=1.0.0

HTML / DOM Fingerprints

JS Globals
window.FLUX_PAYNOW
REST Endpoints
/wp-json/flux-payments-gateway/v1/...
FAQ

Frequently Asked Questions about Flux Payments Gateway for WooCommerce